Other

US Congressional Budget Office China-Suspected Cyberattack

πŸ“… 2025-11-01 🏒 Cisco ASA (firewall)
Primary Source β†—

Incident Details

In early November 2025, the US Congressional Budget Office (CBO) detected and confirmed a cyberattack by a suspected foreign actor. US officials briefed CNN that Chinese state-backed hackers are suspected. Security researcher Kevin Beaumont noted CBO had an outdated Cisco ASA firewall last patched in 2024, vulnerable to bugs being exploited by suspected PRC actors. CBO officials were concerned that hackers accessed internal emails, chat logs, and communications between lawmakers’ offices and CBO researchers. CBO confirmed the incident on November 6, stated immediate containment, and implemented additional security controls. The CBO was a high-value target as its data contains detailed economic projections, budget analyses, and policy impact assessments revealing US government legislative priorities.

Technical Details

Initial Attack Vector
Suspected exploitation of an outdated Cisco ASA firewall (last patched 2024) β€” vulnerable to newly discovered bugs actively exploited by suspected Chinese state-sponsored hackers; suspected PRC/China state-backed actor
Vendor / Product
Cisco ASA (firewall)

Timeline

  1. 2025-11-01 Breach occurred
  2. 2025-11-06 Publicly disclosed