The Office for Budget Responsibility (OBR) inadvertently published its November 2025 Economic and Fiscal Outlook (EFO) online before the official Budget announcement, allowing journalists to access sensitive details by guessing the document's URL. The file, which was not directly linked or listed on the OBR website, was accessible approximately 40 minutes before the Chancellor's statement, revealing key policy measures such as a pay-per-mile charge on electric vehicles and a freeze on tax thresholds. OBR chair Richard Hughes publicly apologized for the incident, describing it as a serious error and expressing personal mortification over the breach of protocol.
In response to the premature disclosure, the OBR has launched a formal investigation overseen by its Oversight Board and supported by former National Cyber Security Centre chief Ciaran Martin, alongside Treasury IT and security specialists. The OBR attributed the leak to a technical error and has committed to reporting the findings to Members of Parliament. The incident has raised concerns about the handling of market-sensitive information and the adequacy of digital security practices within government agencies.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
Following the premature release, the OBR called in cyber expert Ciaran Martin to help investigate the incident and review whether cybersecurity or process failures contributed to the breach. This external review was reported as part of the OBR's response to the disclosure failure.
The UK Office for Budget Responsibility mistakenly published its Budget analysis before the planned release time, creating a leak of market-sensitive fiscal information. The botched publication prompted concern over how the embargo failure occurred.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.