Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is no evidence here that COBOL itself caused U.S. government breaches. A 2017 article reported an association between federal agencies’ IT spending mix and security incidents, while later Government Accountability Office (GAO) reports documented legacy systems with modernization and security problems. Those findings support scrutiny of specific systems and controls—not a claim that one programming language caused breaches.

Did COBOL cause U.S. government data breaches?

The available evidence does not establish that COBOL caused government breaches. The 2017 CSO article behind the headline summarized research by Min-Seok Pang and Huseyin Tanriverdi about federal IT spending and reported security incidents. It did not show that COBOL was responsible for those incidents.

COBOL is a programming language used in some older systems. A system’s age or language is not, by itself, proof of a security weakness. Risk depends on conditions such as whether vulnerabilities can be fixed, whether software and hardware remain supported, how the system is integrated with other technology, and whether effective security controls are in place.

What did the 2017 study report?

As summarized by CSO, Pang and Tanriverdi found that a one-percentage-point increase in the share of new IT development spending was associated with a 5% decrease in security breaches. This is a reported association, not evidence that increasing development spending would cause breaches to fall by that amount, and it is not a finding specifically about COBOL.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The article also quoted the paper as saying that federal agencies spending more on legacy-system maintenance experienced more frequent security incidents, contradicting the idea that legacy systems are necessarily more secure. That claim likewise describes an association; it does not establish that maintenance spending, legacy code, or COBOL caused incidents. The CSO story is secondary reporting, and the available account does not provide enough methodological detail to draw a causal conclusion. Read the 2017 CSO article.

What do the federal incident figures count?

The CSO article reported that federal security incidents rose from 5,503 in 2006 to 67,168 in 2014, citing figures assembled by GAO. These were reported security incidents, a broad category that included events such as denial-of-service attacks and malicious code. They should not be read as counts of confirmed data breaches.

The increase shows that reported incidents grew over that period; it does not identify COBOL as a cause. Incident counts also do not, on their own, explain how many events involved compromised data, which systems were affected, or what underlying weakness enabled an event.

Why can legacy systems create security challenges?

Legacy-system risk is about a system’s actual condition and the agency’s ability to secure and maintain it, not simply the language in which it was written.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Unsupported components: Hardware or software that no longer receives vendor support can make it harder to apply fixes or replace failing components.
  • Known vulnerabilities: A system with documented weaknesses needs remediation, compensating controls, or a plan to replace it if those weaknesses cannot be addressed in place.
  • Integration complexity: Older systems may be tightly connected to other services, making changes difficult to test and deploy safely.
  • Maintenance and staffing: Agencies need both funding and people with the skills to operate, secure, and eventually modernize systems.
  • Weak modernization plans: A plan without clear milestones or a defined retirement path can leave an aging system in service without a credible route to reduce its risk.

These issues can coexist, but they are distinct. Replacing a COBOL application would not automatically fix poor access controls or insecure interfaces; conversely, keeping COBOL does not automatically make a system insecure.

What has GAO found about federal legacy systems?

Historical maintenance spending

GAO reported in 2016 that about 75% of the federal IT budget for fiscal year 2015 went to operations and maintenance. Of roughly 7,000 investments, 5,233 spent all their funds on operations and maintenance. These figures describe FY2015 spending, not current budget levels. GAO’s 2016 report on federal IT spending.

Systems identified for modernization

In 2025, GAO identified 11 federal legacy systems it considered most in need of modernization. Eight used outdated languages, four had unsupported hardware or software, and seven operated with known cybersecurity vulnerabilities. GAO also identified two selected Treasury systems that run COBOL and Assembly. The findings point to specific system and modernization concerns; they do not show that COBOL itself is a vulnerability.

GAO said the government spends over $100 billion on IT each year and that agencies typically report spending about 80% of that on operating and maintaining existing IT. The 80% figure is an agency-reported general pattern in the 2025 report, not a claim about every agency or a COBOL-specific spending share. GAO’s 2025 review of federal legacy systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does the OPM breach show a link to COBOL?

No such link is established by the cited material. The 2017 CSO article mentions the 2015 Office of Personnel Management breach as an example of a major federal breach, but that does not connect the incident to COBOL. GAO’s 2017 review of OPM discusses information-security improvements and remaining work after the breaches; it should be treated as a separate account, not evidence that COBOL was involved. GAO’s review of OPM security improvements.

How should agencies judge whether to modernize?

The useful question is whether a specific system can be secured and supported at acceptable cost—not whether it uses COBOL. A practical assessment should compare:

  • Remediation in place: Can known vulnerabilities be fixed on the existing platform, or are unsupported components preventing effective remediation?
  • Plan and retirement path: Does the agency have documented modernization milestones and a clear disposition for the old system?
  • Whole-life cost: How do the continuing costs of operating and maintaining the system compare with the cost and risk of modernization?
  • Staff capacity: Are qualified personnel available to maintain the current system and deliver a transition safely?

A system may warrant urgent safeguards even if replacement will take years. Modernization is not a substitute for addressing current vulnerabilities, and continued maintenance is not a security strategy unless it includes effective controls and a credible path forward.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.