The U.S. Congressional Budget Office (CBO) has confirmed it was the target of a cybersecurity breach believed to have been carried out by a foreign hacker, raising concerns that sensitive congressional communications and data may have been compromised.
The U.S. Congressional Budget Office has disclosed that it suffered a cybersecurity incident following what officials suspect was a foreign intrusion into its network. The breach has prompted an investigation amid fears that emails and communications between congressional staff and the agency’s analysts could have been accessed.
In a statement CBO spokesperson Caitlin Emma confirmed the incident and said the agency acted swiftly to contain it. “The Congressional Budget Office has identified the security incident, has taken immediate action to contain it, and has implemented additional monitoring and new security controls to further protect the agency’s systems going forward,” Emma said. She added that the investigation is ongoing and that the agency’s work for Congress remains unaffected. “Like other government agencies and private sector entities, CBO occasionally faces threats to its network and continually monitors to address those threats.”
The Washington Post first reported the breach, noting that officials discovered the intrusion in recent days. Although early detection is believed to have limited the damage, several congressional offices are said to have temporarily paused email communications with the CBO out of caution. As a nonpartisan body, the CBO provides lawmakers with economic analysis and cost assessments for proposed legislation. A breach could therefore expose draft reports, budget forecasts, and confidential correspondence, potentially granting foreign actors insight into congressional policy planning.
The attack marks the latest in a string of cyber incidents targeting U.S. government institutions. In December 2024, the U.S. Treasury Department confirmed it had been compromised via the third-party remote support service BeyondTrust. That breach also affected the Committee on Foreign Investment in the United States (CFIUS), which oversees foreign investment for potential national security risks.
Both earlier attacks were attributed to Silk Typhoon, a Chinese state-sponsored hacking group. While officials have not yet publicly attributed the CBO breach, the similarity in methods and timing has fuelled speculation that the same or a related actor may be responsible. The incident underscores the growing cybersecurity challenges faced by U.S. government agencies, which continue to be prime targets for sophisticated nation-state campaigns seeking access to sensitive economic and policy information.
Share this article