On December 30, 2024 — with Washington already half-emptied for the holidays — the US Treasury Department told Congress it had suffered a "major incident." A Chinese state-sponsored actor had reached into departmental workstations and taken unclassified documents. The intruders had not battered down Treasury's defences. They had used a stolen API key belonging to BeyondTrust, the vendor whose remote-support software Treasury employees relied on for help with their computers.
That is the whole modern security problem in one sentence: the vendor you trust to fix your desktop holds a key to your desktop. Reporting through January would indicate the intruders had gone after the Office of Foreign Assets Control — the office that administers US sanctions — and the Committee on Foreign Investment in the United States, which screens foreign deals for national-security risk. If you wanted to know which entities Washington was about to sanction, or which acquisitions it was about to block, those two offices are precisely where you would look. The activity was attributed to the group tracked as Silk Typhoon, and by January 17 the Treasury's own sanctions office was sanctioning a hacker linked to the intrusion against it.
It was a fitting end to a year in which the perimeter had comprehensively stopped mattering. Whatever else 2024 taught, its clearest lesson was arithmetic: your attack surface is not your systems. It is your systems plus everyone holding a key to them — and nobody, including the US Treasury, had a complete list.
The browser extensions that turned
On Christmas Eve, security firm Cyberhaven discovered that its own Chrome extension had been published in a malicious version — an attacker had phished a developer's publishing credentials and pushed a poisoned update straight to users' browsers. Investigation found Cyberhaven was not alone: a cluster of other extensions had been compromised in the same campaign, quietly harvesting session data from anyone who had trusted them. Browser extensions run with sweeping access to everything you do on the web, update silently, and are almost never inventoried by security teams. Attacking them over the holidays, when nobody was watching the publishing dashboards, was the detail that made it professional.
Salt Typhoon's telecom tally grows
December brought no relief in the telecom-espionage story that had dominated the autumn: officials continued adding names to the list of US communications providers penetrated by the Chinese group tracked as Salt Typhoon, with a ninth carrier acknowledged as the year closed. Coming weeks after federal officials had publicly urged Americans to use encrypted messaging apps — an extraordinary thing for a government to advise about its own phone network — the running tally made December feel less like the end of an incident than the discovery of its true size.
Closing a year of firsts
India ended 2024 in a strange position: possessed of a data protection law with no operating rules. The DPDP Act had passed in August 2023, but the draft rules that would make it workable were still unpublished as the year closed — they would land three days into January. In the meantime, the year had delivered a brutal education in why they were needed: BSNL's reported intrusion in May, Hathway's leak of tens of millions of customer records in March, boAt's exposure in February, WazirX's $235 million theft in July, and Star Health's medical records circulating through Telegram bots in the autumn. A country that had digitised faster than almost anywhere on earth spent 2024 discovering the bill, and entered 2025 with the rulebook finally about to arrive.
⏳ Time capsule — December 2024
- Bitcoin had crossed $100,000 for the first time in early December — a threshold that had seemed fantastical a year earlier.
- Security teams spent the holidays doing something new: auditing which browser extensions their staff had installed.
- "Salt Typhoon" and "Volt Typhoon" had entered the general-news vocabulary, a naming convention most people had never heard of twelve months before.
- Every 2025 prediction deck named the same top risk — third parties and identity — and, for once, the predictions turned out right.
The year of the borrowed key
December 2024's Treasury breach reads now as the overture to everything that followed. The BeyondTrust key was the same lesson the Salesloft Drift tokens would teach at scale eight months later, and the F5 and Klue compromises after that: attackers had permanently stopped attacking companies and started attacking the trust between companies. Silk Typhoon's operators drew sanctions in January 2025 and kept appearing in advisories through the year. The Cyberhaven campaign turned browser-extension governance from a niche worry into a standard enterprise control. And India's rulebook, three days away as the year ended, began the march that would end with the DPDP Rules notified in November 2025 — the subject of much of this archive's later coverage.