Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On January 17, 2025, the U.S. Treasury Department sanctioned two China-linked cyber actors for separate incidents: Shanghai-based Yin Kecheng, whom Treasury associated with a breach of its own Departmental Offices network, and Sichuan Juxinhe Network Technology Co., Ltd., which Treasury said was directly involved in the Salt Typhoon campaign against U.S. telecommunications and internet-service-provider infrastructure. The two incidents were addressed in one sanctions announcement, but the available facts do not establish that they were the same hack or that the two designated parties had identical roles.

Who Treasury sanctioned—and for what

The Treasury Department’s Office of Foreign Assets Control (OFAC) designated both parties on January 17, 2025. Treasury described distinct connections to the two incidents:

Designated party Treasury’s stated connection Incident
Yin Kecheng, based in Shanghai Treasury associated Yin with the recent compromise of the Departmental Offices network. The breach of Treasury’s own network.
Sichuan Juxinhe Network Technology Co., Ltd. Treasury said the company had direct involvement in Salt Typhoon. Intrusions into infrastructure at major U.S. telecommunications and internet-service-provider companies.

The State Department separately described Yin as affiliated with China’s Ministry of State Security. These are U.S. government attributions; the sanctions announcement does not make the Treasury breach and Salt Typhoon a single operation.

How the Treasury network was breached

Treasury learned of the separate incident on December 8, 2024, after BeyondTrust reported that a key used to secure a cloud-based remote-support service had been stolen. The key enabled remote access to several Treasury employee workstations. The Associated Press reported that Treasury told lawmakers there was no evidence at that time that the actor was continuing to access Treasury information.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This account describes access through a compromised vendor-service key. It should not be conflated with Salt Typhoon’s intrusions into commercial telecom infrastructure; the public information summarized here does not establish that the same access method was used in both incidents.

What is Salt Typhoon, and how broad was its reach?

Salt Typhoon is the name used for the cyber campaign that Treasury said had compromised the network infrastructure of multiple major U.S. telecommunications and internet-service-provider companies. Treasury said the activity had been underway since at least 2019.

On December 4, 2024, the White House said at least eight U.S. telecommunications firms and dozens of nations had been affected. Officials said communications of senior government officials and prominent political figures may have been accessed. Those are dated minimums and assessments, not a final count: investigations were continuing, and the public account does not identify every affected company or every communication that may have been accessed.

What the sanctions do

OFAC sanctions block the designated persons’ property and interests in property when that property is in the United States or in the possession or control of U.S. persons. Treasury also said that entities owned 50% or more by blocked persons are blocked, even if they are not separately named.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • U.S. persons, and transactions taking place in the United States, are generally prohibited from dealing with blocked persons or their blocked property unless an authorization or exemption applies.
  • The practical effect is to restrict access to property within U.S. jurisdiction and covered dealings; the designation is not, by itself, a public accounting of every asset or transaction affected.
  • The rules concern U.S.-linked property and transactions. The announcement does not mean that every person or company worldwide is automatically barred from all dealings with the designated parties.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What else did the U.S. government announce?

The State Department’s Rewards for Justice program offered up to $10 million for information leading to the identification or location of qualifying foreign-government-directed cyber actors targeting U.S. critical infrastructure. “Up to” is a ceiling, not a guaranteed payment: the offer applies to qualifying information under the program’s terms.

Deputy Treasury Secretary Adewale O. Adeyemo said Treasury would continue using its authorities to hold malicious cyber actors accountable, including those targeting the department. The January 17 announcement thus paired financial restrictions with public attribution and a reward offer, while assigning different roles to the Treasury-breach actor and the company linked to Salt Typhoon.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.