2024 CGI Federal / GAO — Confluence exploitation; ~6.6k employee and contractor PII
Data compromised
Federal employee and related contractor PII as characterized in GAO public confirmation
Technical writeup
GAO publicly confirmed that CGI Federal, a contractor supporting financial management systems, notified it on 17 January 2024 of a breach touching roughly 6,600 individuals—primarily current and former GAO employees from 2007–2017 plus some GAO business partners. CGI Federal attributed the incident in press statements to exploitation of an Atlassian Confluence vulnerability consistent with CISA’s October 2023 active-exploitation advisory track. GAO described offering identity-theft monitoring to impacted parties.
Root cause
Known Confluence vulnerability exploitation against contractor-operated collaboration stack (per CGI Federal statement summarized by trade press)