In December 2024, the United States Department of the Treasury notified Congress that it had suffered what officials described as a "major cybersecurity incident." The attacker was a Chinese state-sponsored group. The entry point was not a Treasury system. It was a compromised API key belonging to BeyondTrust - a third-party vendor providing remote support services to the Treasury.
BeyondTrust alerted Treasury on 8 December that a threat actor had obtained one of its API keys and used it to override security controls, gain remote access to Treasury workstations, and access unclassified documents. The API key gave the attacker the same access rights as the legitimate vendor support function. Every system involved saw authorised traffic from an authorised source. The access was entirely legitimate in appearance. The documents were accessible because the vendor was permitted to access them as part of its support role.
This is the third-party vendor access problem. It is one of the most consistently exploited gaps in enterprise security and one of the least solved. Organisations extend access to vendors, integrators, and service providers because they need to. Those vendors hold credentials, tokens, and keys that carry the same permissions as an internal privileged user. When those credentials are compromised - through a breach of the vendor, through theft, or through insider abuse - the attacker inherits all of that access without triggering any internal alarm.
The industry's response has been to tighten vendor access controls, reduce standing permissions, implement just-in-time access, and audit third-party relationships more rigorously. All of that is right. None of it addresses the execution boundary. A vendor with legitimate access, or an attacker holding a vendor's legitimate key, still faces no confirmed authority requirement before accessing sensitive systems and documents.
GoFirm operates at exactly this boundary. Third-party vendor access to sensitive environments is a configurable action type. Before a vendor session accesses classified or sensitive systems, GoFirm routes a confirmation request to the named authority within the organisation responsible for that access category. The vendor either has a confirmed authorisation in place or the access does not proceed. An attacker holding a compromised API key cannot produce that confirmation from the named internal authority.
The additional layer that matters here: every vendor access event is signed, timestamped, and permanently recorded in GoFirm's append-only audit trail. When a regulator, an oversight body, or Congress asks what the vendor accessed, when, and whether it was authorised, the answer is in the record. In the Treasury's case, the answer to that question had to be reconstructed from system logs after the fact. GoFirm makes it available before the question is even asked.
A Chinese state actor used a vendor's API key to access US Treasury workstations. The vendor access was permitted. The execution boundary was unguarded. That is what GoFirm prevents.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.
References
1. Hornetsecurity, Major Cybersecurity Incidents of 2025 and Lessons Learned, January 2026
2. Hornetsecurity, ibid.
