Key US government body says it might have been breached, with thousands of employees affected

Cyberattack
(Image credit: Cyberattack)

Thousands of US government employees may have had their private data stolen in a breach that happened within a third-party contractor.

Sometime during January 2024, CGI Federal, an IT services provider mostly focused on cybersecurity, suffered a data breach in which threat actors stole sensitive data belonging to about 6,600 employees of the U.S. Government Accountability Office (GAO), Reuters reports

The GAO is a non-partisan government agency that provides auditing, evaluative, and investigative services for the US Congress. It is described as “the supreme audit institution of the federal government of the United States”.

Confirmed attack

Following the incident, CGI Federal sent a breach notification letter to affected individuals, Reuters further reported. In the letter, the company said the attackers stole "names, social security numbers, addresses, and some banking information." To steal this information, the attackers exploited a vulnerability in an externally provided platform, the letter also said, without explaining further. 

The data breach was later confirmed to Nextgov by GAO spokesperson Charles Young: “On January 17 of this year, CGI Federal, a contractor involved in GAO’s financial management systems, notified GAO of a data breach impacting approximately 6,600 people, primarily current and former GAO employees from 2007 to 2017, as well as some companies doing business with GAO,” Young said. 

“GAO immediately took steps to begin identifying and notifying the impacted individuals regarding the release of PII (personally identifiable information),” the statement added. 

A CGI representative recently testified in front of the US Congress, during which they said the company provides IT protection for “100 participating agencies”, Reuters said. The representative further elaborated that the State, Justice, Commerce, and Labor departments, all used the company’s services, as well as the Federal Communications Commission (FCC) and the US State for International Development (USAID).

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
US coast guard boat
US Coast Guard paychecks delayed by cyberattack
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
Major breach hits employee screening firm - 3.3 million affected as hackers steal DISA data
China
US Government officials urged to lock down devices amid telecoms breach
China US flags cropped
CISA says ‘no indication’ other US government agencies affected in Treasury hack
The International Civil Aviation Organization in Montreal, Canada
International Civil Aviation Organization investigating possible records data breach
Latest in Security
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
DeepSeek
Fake DeepSeek installers are infecting your device with dangerous malware
AI tools.
Not even fairy tales are safe - researchers weaponise bedtime stories to jailbreak AI chatbots and create malware
Data leak
Top California sperm bank suffers embarrassing leak
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
ransomware avast
Billions of credentials were stolen from businesses around the world in 2024
Latest in News
Oracle
Oracle unveils multi-billion dollar investment in UK cloud and AI
Close up of PS5 DualSense controller leaning on a PS5
Sony patents PlayStation controller that you can charge by leaving in sunlight
Woman disgusted by her laptop
Embarrassing Windows 11 bug that deleted Copilot app is now fixed – but will anyone outside of Microsoft care?
The redisgned Plex app displayed across three iPhone screens
Plex is raising its prices and making a great key feature no longer free – here's why some subscribers are signing up to the Lifetime Pass before the rise
Canon March 2025 launch teaser
Canon teases two big vlogging camera launches for next week – and one looks to be the PowerShot V1
Analogue 3D
You'll have to wait a bit longer if you've pre-ordered the Analogue 3D as shipping has been delayed until later this year