2025 Network compromise — 2.4M affected
Data compromised
Sensitive government and financial institution data
Technical writeup
U.S. Department of the Treasury experienced a network compromise in January 2025. Treasury sanctioned Zhou Shuai and Shanghai Heiying Information Technology for illegally acquiring and selling data from U.S. critical infrastructure networks. Separate OCC breach: attackers gained access to 103+ email accounts with ~150,000 emails over a year.
Root cause
Network compromise; unauthorized access to critical infrastructure systems.