US Congressional Budget Office hit by suspected cyberattack – here’s what we know

  • The US Congressional Budget Office has confirmed a cyber incident
  • The attack may have been from a foreign adversary
  • This is one of many recent incidents targeting US government institutions

The US Congressional Budget Office has confirmed it was targeted in a cybersecurity incident it suspects can be attributed to a foreign hacker.

The non-partisan accounting service holds financial records and assessments for the legislative branch, and holds sensitive government information.

“The Congressional Budget Office has identified the security incident, has taken immediate action to contain it, and has implemented additional monitoring and new security controls to further protect the agency’s systems going forward,” CBO spokesperson Caitlin Emma said in a statement.

A continuous threat

It’s very possible that sensitive data was compromised in the attack – and specific concerns have arisen around emails exchanged between analysts and congressional offices. It’s likely a breach could expose economic forecasts, draft reports, personal contact details, and policy plans.

Incidents like these are sadly all too common, and critical infrastructure suffers almost continual attacks, both from private hackers and state-backed attackers – with the intention of exfiltrating data, espionage, disruption, or occasionally for profit.

“The incident is being investigated and work for the Congress continues. Like other government agencies and private sector entities, CBO occasionally faces threats to its network and continually monitors to address those threats,” the statement continues.

This isn’t the first time a congressional department has been targeted. In late 2024, the US Congressional staff were exposed in a Library of Congress email hack which compromised almost a year’s worth of correspondence between legislative staff and researchers in what was labelled as a ‘foreign adversary’ incident.

Although these may seem like small-scale attacks that don’t result in dramatic takeovers of government institutions or shut downs, the incidents could give foreign adversaries valuable information into upcoming policies, economic expectations, or even network access. Access to internal communications could lead to sophisticated social engineering attacks aimed at employees, leading to even more serious incidents.

Via NextGov

Read more @ TechRadar

Latest posts

Apple is turning Siri into an AI bot that’s more like ChatGPT

Apple is planning a big Siri overhaul that will transform the voice assistant into an AI chatbot built directly into its iPhone and Mac,...

Anthropic’s new Claude ‘constitution’: be helpful and honest, and don’t destroy humanity

Anthropic is overhauling Claude's so-called "soul doc." The new missive is a 57-page document titled "Claude's Constitution," which details "Anthropic's intentions for the model's...

Apple is reportedly working on an AirTag-sized AI wearable

Apple is working on an AI-powered wearable pin with cameras and microphones designed to pick up a user's surroundings, according to a report from...

Everyone can hear your TV in their headphones using this transmitter

Sennheiser’s new Auracast transmitter can be purchased as part of a bundle with its new wireless headphones. | Image: Sennheiser As we've previously lamented, one...

Blue Origin’s Starlink rival TeraWave promises 6 terabit satellite internet

The Blue Origin New Glenn rocket lifts off at Launch Complex 36 in its second launch attempt at Cape Canaveral Space Force Station on...

Apple is reportedly developing a wearable AI pin

Apple will reportedly try to succeed where Humane failed (miserably). On Wednesday, The Information reported that the iPhone maker is working on an AI...

Apple is reportedly overhauling Siri to be an AI chatbot

Apple has been spinning its wheels for many months over its approach to artificial intelligence, but a strategy finally appears to be emerging for...

Marshall’s new Heddon hub adds multi-room audio to speakers with Auracast

Marshall plans to add seamless multi-room audio to its Bluetooth speakers via a newly announced music streaming hub called Heddon. The $300 hub makes...

A new LinkedIn phishing scam is targeting executives online – make sure you don’t fall for this

Sophisticated LinkedIn phishing uses fake job ads to target executives Attacks employ DLL sideloading and Python tools to install remote access trojansReliaQuest warns phishing...

Report: Apple does about-face on Siri chatbot — and it might compete directly with ChatGPT and Google

Apple promised us this was never the plan...until we guess, it became the plan: A new report from Apple soothsayer Mark Gurman says Apple...