The Congressional Budget Office (CBO) confirmed that it successfully expelled threat actors from its systems following a sophisticated cyberattack that occurred two weeks prior. CBO Director Phillip Swagel testified before the House Budget Committee, stating that operations have returned to normal and that there is no further evidence of unauthorized access to CBO email systems. The agency acted swiftly to notify stakeholders and engaged both federal partners and private sector security specialists to assist in the investigation and remediation efforts.
The nature of the attack involved unauthorized access to a subset of CBO's email accounts, and the incident is still under active investigation with the involvement of multiple government agencies, including the House, Senate, and U.S. Capitol Police. Details about the attack and ongoing security measures are being withheld from public disclosure to avoid impeding remediation activities, with further updates promised in a closed-door setting. The CBO's response was praised by lawmakers for its urgency and transparency, and additional funding has been allocated to bolster the agency's cybersecurity posture.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
CBO Director Phillip Swagel testified that hackers had been expelled from the agency's email systems and that the incident had been contained. This public statement marked the first official confirmation of the response status.
The Congressional Budget Office experienced a cyberattack affecting its email systems. The intrusion was later described by CBO leadership as having been contained and the attackers removed.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.