The Congressional Budget Office (CBO), a nonpartisan federal agency providing budget and economic analysis to Congress, confirmed a cybersecurity incident attributed to a suspected foreign threat actor. Officials reported that the breach may have exposed sensitive communications between lawmakers and CBO analysts, as well as internal data such as draft reports and economic forecasts. The CBO responded by containing the incident, implementing additional monitoring, and enhancing security controls to protect its systems. The agency emphasized that work for Congress continues while the investigation is ongoing.
The breach was detected early, according to officials, but concerns remain about the potential exposure of confidential information. Some congressional offices have reportedly suspended email communications with the CBO as a precaution. This incident follows a pattern of recent cyberattacks targeting U.S. government agencies, including the Treasury Department and the Committee on Foreign Investment in the United States, with attribution in those cases linked to Chinese state-sponsored actors. The CBO has requested increased funding to bolster its cybersecurity and IT infrastructure in response to the growing threat landscape.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
By November 10, reporting indicated the cybersecurity incident at the Congressional Budget Office was still ongoing rather than fully resolved. Coverage continued to characterize the threat as linked to a suspected nation-state actor.
Following reports of the cyberattack, the Congressional Budget Office began putting additional security controls in place to contain risk and respond to the breach. This marked the agency's first publicly reported operational response to the incident.
The U.S. Congressional Budget Office was hit by a cybersecurity incident that multiple reports described as a suspected foreign or nation-state cyberattack. The incident affected the agency that provides budget and economic analysis to Congress.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
7 references tracked. Mallory keeps watching after this page renders.
politico.com
Open sourcescworld.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.