Desk live·
ForensicPost
Breaches/Public sector/File 25-1106b

Congressional Budget Office Compromise Linked to Unpatched Cisco ASA

The Congressional Budget Office confirmed a compromise in November 2025, with reporting identifying an unpatched Cisco ASA appliance as the weakness.

Constructed geometry · not a chart of case data
TargetCongressional Budget Office
ActorUnattributed
S. Rosler11 min readConfidence: medium2 sources reviewed

The Congressional Budget Office confirmed in November 2025 that it had been hacked. Reporting identifies the primary technical weakness as an unpatched Cisco ASA firewall.

The Product Category, For The Fifth Time This Year

This desk filed at 25-0805 that the 2025 exploitation record is dominated by devices sold as security products — Ivanti, NetScaler, Fortinet, SonicWall — and set out why: internet-facing by design, parsing untrusted input by design, trusted by everything behind them by design.

A firewall appliance at a legislative agency is that argument with the least sympathetic detail attached. Unlike the zero-days at 25-0109 and 25-0624, this is reported as an unpatched device — a known defect with an available fix.

The Corpus Should Not Be Glib About It

The unpatchable argument at 26-0405 holds that vulnerability volume exceeds remediation capacity, and this desk has repeatedly said that patch coverage is a poor metric — at 25-0723, where patched servers still served attackers holding stolen keys.

None of that excuses a perimeter appliance. The corpus made exactly this distinction at 25-0814: a firewall in front of an organisation holding sensitive data is not a long-tail asset competing for attention. It is the front door, and it is a small enough population to track.

What The Agency Holds

A budget office produces cost estimates and economic analysis for legislation before it is public. Its correspondence describes what is being drafted, by whom, and with what fiscal implications.

That is the mail-store argument at 25-1212 and 25-0408 — the value is the reasoning and the relationships, not a record count. Graded medium: this desk has not established what was accessed or by whom, and no actor is named here.

How we reported this

Compiled from public reporting, listed below. The identification of the appliance as the entry point follows that reporting. Scope and attribution are not established. Corrections: corrections@forensicpost.com.

Sources
  1. Congressional Budget Office confirms it was hackedTechCrunch
  2. Congressional Budget Office Cisco ASA firewall breachRescana
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary