iTnews Asia
  • Home
  • News
  • Security

US agency says it was alerted to breach by contractor

US agency says it was alerted to breach by contractor

Affecting about 6,000 current and former GAO employees.

By Raphael Satter on Feb 13, 2024 11:23AM

The US Government Accountability Office said Monday that CGI Federal, an IT contractor and unit of CGI Inc., notified the agency of a data breach last month affecting about 6,000 current and former GAO employees.

The GAO, a research arm of Congress, said in a statement the data involved personally identifiable information on employees including some people who worked there from 2007 to 2017.

A breach notification letter seen by Reuters said that the data contained "names, social security numbers, addresses, and some banking information." The letter said the breach had been carried out by a "threat actor exploiting a vulnerability in an externally provided platform" but didn't delve into specifics.

GAO spokesperson Chuck Young said his agency was notified about the breach on January 17 but referred questions about its impact to CGI. CGI Federal did not immediately return messages seeking comment.

CGI, which has recently pivoted toward cybersecurity, has many contracts with the federal government. In recent congressional testimony, a CGI official said that the company has provided IT protection for "100 participating agencies" through the U.S. cybersecurity agency tasked with protecting federal networks.

In the same testimony, GCI said it provided cybersecurity services to the State, Justice, Commerce, and Labor departments, the Federal Communications Commission, and the United States Agency for International Development.

The cybersecurity agency did not immediately respond to a request for comment about CGI. The FBI did not immediately return emails.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright Reuters
© 2019 Thomson Reuters. Click for Restrictions.
Tags:
cgi federal gao security

Related Articles

  • The real-life Tom & Jerry chase
  • How can we bolster our resilience against AI-enabled e-mail attacks?
  • Qantas hit by cyberattack, data of six million customers exposed
  • Your organisation’s physical security can be a gateway for cybercriminals
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

The real-life Tom & Jerry chase

The real-life Tom & Jerry chase

How can we bolster our resilience against AI-enabled e-mail attacks?

How can we bolster our resilience against AI-enabled e-mail attacks?

Singapore sees no 'juice jacking' at transport charging stations, wi-fi points

Singapore sees no 'juice jacking' at transport charging stations, wi-fi points

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.