The US government has announced sanctions against a Chinese organization with links to Salt Typhoon, the hacking group responsible for largest telecoms hack in US history.
The Department of the Treasury’s Office of Foreign Assets Control (OFAC) announced on Friday that it sanctioned a China-based cybersecurity company known as Sichuan Juxinhe Network Technology, which is said to be directly linked to the Chinese-backed Salt Typhoon hacking group.
Salt Typhoon was recently recognized as the largest telecommunications hack in US history, after breaching at least nine US telecom and internet providers, including AT&T and Verizon, to gain access to private communications of senior US government officials and political figures.
Hackers have also hacked into systems used by law enforcement agencies for court-authorized collection of customer data, potentially accessing sensitive data such as the identities of the targets of China to monitor the US.
In its press release on Friday, OFAC said that Sichuan Juxinhe had “direct involvement in the exploitation of telecommunications companies and internet service providers in the US.”
Treasury hackers are allowed
OFAC also announced sanctions against Yin Kecheng, a Shanghai-based cyber actor, who US officials claimed was responsible for recent widespread hack of the US Treasury.
The hack, which took place in late December, saw hackers use a private key stolen from BeyondTrust – a cybersecurity company that provides identity access tech to large organizations and government departments – to gain remote access to certain Treasury employee workstations.
A cyberattack allows hackers to – another Chinese state-backed group known as Silk Typhoon – to target various departments within the US Treasury, including its sanctions office.
According to OFAC, Yin Kecheng has been a cyber actor for more than a decade and is affiliated with China’s Ministry of State Security, an intelligence and security agency responsible for the country’s foreign intelligence collection.
US Treasury official Adewale O. Adeyemo said in a statement on Friday: “The Department of the Treasury will continue to use its authorities to hold accountable malicious cyber actors who target Americans, our companies , and the United States government, including those targeting the Treasury Department.”
Earlier this month, the The US government has sanctioned another China-based cybersecurity company because of its alleged links to a government-backed hacking group known as Flax Typhoon. The Treasury said the company, Integrity Technology Group, was involved in “numerous incidents of computer intrusion against US victims,” including critical US infrastructure.