CGI Federal, a contractor to the U.S. Government Accountability Office (GAO), told news outlets that exploitation of Atlassian Confluence was responsible for a breach affecting GAO-related data. That is the contractor’s reported attribution—not a publicly available, independently confirmed forensic account. Contemporaneous reports put the number of affected people at about 6,000 to 6,600, but the full scope and exposed data were not established publicly.
What vulnerability was linked to the breach?
Reporting connected the incident to warnings issued in October 2023 about active exploitation of Atlassian Confluence Data Center and Server. TechRadar Pro identified the vulnerability as CVE-2023-22515. That CVE identification comes from secondary technical reporting; the sources cited here do not include an official Atlassian or CISA advisory.
CGI Federal said the breach involved exploitation of Confluence, according to Nextgov/FCW and CyberScoop. The available reporting does not establish the affected system’s exact version, how attackers gained access, or the sequence of events. It therefore does not support treating a complete attack chain as confirmed.
How many people were affected?
Contemporaneous reports gave differently framed estimates, rather than a reconciled final count.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
| Report | Figure and scope |
|---|---|
| Nextgov/FCW, February 2024 | Approximately 6,600 people, primarily current and former GAO employees, as well as some firms doing business with the agency. |
| Reuters via Investing.com, February 2024 | 6,000 current and former GAO employees. Reuters said it could not determine the breach’s full size and scope. |
The figures may reflect different reporting or population descriptions. Neither account establishes a final audited total.
What information was exposed?
The reports cited here do not establish a complete inventory of affected data or verify specific exposed fields. CGI Federal said it was working with authorities and clients to identify and disclose data affected by the Confluence exploitation, as reported by Nextgov/FCW. That statement described work in progress, not a completed accounting of the data.
Rank #2
- WatchGuard Firebox T45 tabletop appliances bring enterprise-level network security to small office/branch office and retail environments. These appliances are small-footprint, cost-effective security powerhouses that deliver all the features present in WatchGuard’s higher-end UTM appliances, including all security capabilities, such as AI-powered anti-malware, threat correlation, and DNS-filtering.
- 5G and Wi-Fi 6 enabled models available. Up to 3.94 Gbps firewall throughput, 5 x 1Gb ports, 30 Branch Office VPNs
- Zero-touch deployment makes it possible to eliminate much of the labor involved in setting up a Firebox to connect to your network - all without having to leave your office. A robust, Cloud-based deployment and configuration tool comes standard with WatchGuard Firebox appliances. Local staff connects the device to power and the Internet, and the appliance connects to the Cloud for all its configuration settings.
- Firebox T45 models make network optimization easy. With integrated SD-WAN and optional 5G technology, you can ensure failover to the cellular network, minimize disruptive connectivity, and establish secure and reliable connections for small offices.
- Standard Support includes 24x7 access to technical support, with an unlimited number of incidents with a targeted response time of 24 hours for low priority, 8 hours for medium priority, 4 hours for high priority, and live calls for critical priority. Support is Web-Based and Phone-Based.
Was GAO itself hacked, or was the breach through a contractor?
CGI Federal is GAO’s contractor, and the breach was reported to GAO by CGI Federal in January 2024. Public accounts described the incident as affecting GAO-related data and attributed the Confluence exploitation to CGI Federal’s account. The sources cited here do not provide an independent forensic finding that resolves precisely which organization’s systems were compromised or how the intrusion occurred.
Reuters reported that the breach’s impact beyond GAO had not been publicly disclosed. The available accounts do not establish that other agencies or CGI Federal clients were affected.
Rank #3
- Integration with Unifi Controller. Powerful firewall performance
- Convenient VLAN support. QoS for enterprise VoIP
- VPN server for secure communications. 10/100/1000Base-T
- 3 Ports - Management Port - SlotsGigabit Ethernet - Wall Mountable, Desktop
- Refer instruction manual for troubleshooting steps.
What did GAO and CGI Federal do after the disclosure?
GAO was reported to be investigating and offering identity-theft monitoring services to affected people. CGI Federal said it was working with authorities and clients to identify and disclose affected data. These were reported response steps; they do not show that the investigation or scope assessment was complete.
Atlassian’s response, as quoted by CyberScoop, was that “protecting customers’ instances is our top priority, and we are committed to supporting our customers in taking timely action to protect their data.” The sources cited here do not provide patch-status guidance for the affected system.
What remains unconfirmed?
- The exact Confluence version and system configuration involved.
- The initial access date, attack sequence, and attacker identity.
- A complete list of exposed data and a final affected-person count.
- Whether the incident affected additional agencies, clients, or systems.
These limits matter because the public account rests on contemporaneous news reporting of statements and estimates, not a published GAO forensic report or final investigation findings.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

