The US sanctions a China-based cybersecurity company involved in the Salt Typhoon hacks and a Shanghai-based hacker involved in the recent US Treasury breach
Treasury's OFAC is sanctioning Yin Kecheng, a Shanghai-based cyber actor who was involved with the recent Department of the Treasury network compromise. … X: Nicole Perlroth / @nicoleperlroth : BIG: Treasury says Yin Yechen, a Shanghai based hacker, and Sichuan Juxinhe Network Technology Co. - “a hacking company with strong ties to China's Ministry of State Security” are responsible for the worst U.S. telecom hacks in history and the recent hack of Treasury. Carly Page / @carlypage_ : The US government has announced sanctions against a Chinese organization with links to Salt Typhoon, along with a cyber actor it says was responsible for the December hack of the US Treasury https://techcrunch.com/... Forums: BeauHD / Slashdot : US Sanctions Chinese Firm, Hacker Behind Telecom and Treasury Hacks
Context & Ripple Effects
This action follows reports that Chinese government hackers breached OFAC and other Treasury offices, bringing the sanctions administrator itself into the incident’s scope. It also extends a January pattern in which Washington sanctioned Integrity Technology over alleged Flax Typhoon links.
By naming both a company tied to Salt Typhoon and an individual tied to the Treasury compromise, OFAC is connecting telecom-targeting activity and intrusion into a core U.S. economic-security agency to specific China-based actors.
First-order effects
- Sichuan Juxinhe Network Technology Co. and Yin Kecheng are formally designated by OFAC, placing the firm and individual at the center of U.S. attribution for Salt Typhoon activity and the Treasury compromise, respectively.
- Treasury and OFAC can use the designations to publicly distinguish the alleged telecom and Treasury operators from the broader Chinese cyber ecosystem.
Second-order effects
- The move adds pressure on other China-based cybersecurity vendors alleged to have state links, following the earlier reported breach of OFAC and other Treasury offices and the Integrity Technology designations.
- U.S. telecom operators and government agencies gain a clearer set of named actors around which to prioritize incident investigation, vendor scrutiny, and threat-sharing.
Third-order effects
- If these designations continue, sanctions may become a more regular mechanism for converting cyber attribution into economic restrictions against companies as well as individual operators.
- The pattern points toward a more explicit U.S. treatment of ostensibly commercial cybersecurity firms with alleged state ties as part of the state-backed cyber threat landscape.
The trend: The U.S. is increasingly pairing public cyber attribution with targeted economic sanctions against alleged state-linked operators and their corporate enablers.