Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The agency hit by a security incident was the Congressional Budget Office (CBO), which provides Congress with budgetary and economic analysis. CBO later reported that an intruder accessed about 29,500 emails across 22 mailboxes between July and November 7, 2025. The agency said none of the reviewed emails contained classified information; it has not publicly identified the actor in the sources available here.

What happened at the Congressional Budget Office?

On November 6, 2025, CyberScoop reported that CBO had acknowledged a security incident. At the time, spokesperson Caitlin Emma said the agency had identified the incident, taken immediate steps to contain it, and added monitoring and security controls. She also said that the incident was under investigation while work for Congress continued. CyberScoop’s contemporaneous report captured that initial public account.

CBO’s later account in its FY2027 appropriations request gave more detail: Microsoft notified the agency in early November 2025 that a sophisticated threat actor had gained unauthorized access to a subset of CBO emails. CBO says it worked with government and industry security partners to remove the actor from the email system, strengthen its systems, and investigate.

What information did the investigation find was accessed?

CBO says its investigation found that about 29,500 emails from 22 mailboxes were accessed between July and November 7, 2025. The agency reported that none of the reviewed emails contained classified information. That is a finding about the emails reviewed, not a claim that no sensitive or unclassified information was involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

About 2,800 of the accessed emails—less than 10 percent—included a house.gov or senate.gov address somewhere in an email chain, according to CBO. This is a count of accessed emails containing such an address in the chain. It is not a count of unique congressional correspondents, lawmakers, or staffers, and it does not establish that all messages in those chains were written by or sent to Congress.

Was classified information exposed?

CBO said its review found no classified information in the accessed emails. The agency also said it was conducting a risk analysis of the emails. The FY2027 request does not provide the final result of that analysis or settle whether particular people were notified, so neither a completed risk determination nor notification decisions should be inferred from the reported figures.

Who was behind the intrusion?

The sources do not establish the threat actor’s identity or confirm a country attribution. Early reporting described foreign involvement as suspected or reported, while CBO’s later account said mailbox patterns suggested interest in national-security work, cybersecurity, and agency leadership. Those apparent areas of interest are not proof of who carried out the intrusion.

How did CBO respond?

CBO says its security partners found no evidence that the actor remained on its network or systems. The agency reported a set of containment, investigation, and hardening measures:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Decommissioning Citrix and removing and replacing Cisco Adaptive Security Appliances (ASAs).
  • Conducting forensic analysis of network components and severing persistence mechanisms.
  • Changing VPN providers and resetting email and administrative accounts, along with multifactor authentication (MFA) registrations.
  • Reviewing accessed emails, performing risk analysis, and establishing alternate communications.
  • Installing new network hardware and configuring it with additional security features.

CBO also described broader security work: centralizing logs, auditing public-key infrastructure, strengthening security operations and virtual desktop protections, and improving authentication, intrusion detection and prevention, website and endpoint monitoring, and incident-response capabilities.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What security improvements and funding did CBO describe?

CBO’s FY2027 request describes a continuing effort to build layered defenses, strengthen identity and access controls, improve logging and monitoring, and adopt a zero-trust architecture. The document says CBO expected to devote more than $7.1 million to cybersecurity activities in FY2026 and requested $5.4 million for FY2027. The first figure is an agency expectation and the second is a budget request; neither should be read as a confirmed final appropriation.

The incident account and planned investments are detailed in CBO’s FY2027 appropriations request. For the announcement as it was reported when the incident first became public, see CyberScoop’s November 6, 2025 coverage.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.