← U.S. Department of the Treasury

2025 Network compromise — 2.4M affected

2025 2.4M records affected Share on X

Data compromised

Sensitive government and financial institution data

Technical writeup

U.S. Department of the Treasury experienced a network compromise in January 2025. Treasury sanctioned Zhou Shuai and Shanghai Heiying Information Technology for illegally acquiring and selling data from U.S. critical infrastructure networks. Separate OCC breach: attackers gained access to 103+ email accounts with ~150,000 emails over a year.

Root cause

Network compromise; unauthorized access to critical infrastructure systems.

References