Get all your news in one place.
100’s of premium titles.
One app.
Start reading
Kiplinger
Kiplinger
Business
Christy Bieber

DOGE Compromised Social Security Data, Says Whistleblower

A Social Security card that appears to be tampered with by identity theives.

If there's one piece of identifying data you don't want falling into the wrong hands, it's your Social Security number. That's why recent allegations from a whistleblower are so troubling.

On August 26, Charles Borges, the chief data officer (CDO) at the Social Security Administration (SSA), alleged that DOGE (Department of Government Efficiency) employees copied ultrasensitive data to a cloud server that does not meet government standards for protecting data privacy.

The whistleblower complaint was submitted by the Government Accountability Project.

The database that Borges said was copied contains records of every Social Security number the federal government has issued to Americans, along with names, addresses and birthdates.

DOGE copies data to the cloud in a "high-risk" project

The Government Accountability Project assisted Borges in submitting a protected whistleblower disclosure to the Office of the Special Counsel, as well as to congressional committees.

In the whistleblower complaint, Borges alleges that DOGE officials employed by SSA have created a live copy of a critical database, known as the NUMIDENT file, in a cloud environment.

The complaint includes emails from John Solly, a software engineer working at Social Security, who asked a career agency employee about making the copy shortly after the Supreme Court allowed DOGE access.

The NUMIDENT file is a database with over 548 million Social Security numbers, along with the identifying information of everyone living or dead who has ever had a Social Security number.

The complaint also enumerates the following allegations.

  • The virtual cloud environment on the internal agency server was accessible only by DOGE employees.
  • DOGE was warned that copying the data could make Americans vulnerable to identity theft, but proceeded with the project anyway.
  • No verified audit or oversight mechanisms were in place to determine what the data was being used for or whether it was properly secured, and there was no independent security monitoring of the cloud environment.
  • DOGE briefly circumvented a March 20 temporary order prohibiting access to certain Social Security data.
  • DOGE officials bypassed normal procedures to receive "improper" access to other databases with sensitive information.

The complaint included a copy of an email from Joe Cunningham, the agency's acting chief information security officer, warning that "after a thorough review, we have determined that this request [to copy the information] poses a high risk."

Potential risk from DOGE actions

Borges' complaint shows that, despite privacy concerns, Cunningham requested and received the approval of Michael Russo, a senior DOGE-aligned official at Social Security, to sign off on the project of copying the database to the cloud server, despite making clear that his recommendations to anonymize the personal data had not been followed.

Further emails revealed that the data was transferred despite official security assessments warning that if it were compromised, it would have a "catastrophic impact" on Social Security beneficiaries.

"I have determined the business need is higher than the security risk associated with this implementation and I accept all risks," Aram Moghaddassi, Social Security's chief information officer, and a former employee of Elon Musk at X and Neuralink, wrote in a July 15 memo, as reported by NPR.

Borges disagrees with this assessment. "Should bad actors gain access to this cloud environment, Americans may be susceptible to widespread identity theft, may lose vital health care and food benefits, and the government may be responsible for reissuing every American a new Social Security number at great cost," Borges' complaint said.

No evidence of a data breach

While Borges' allegations are serious, the good news is that it appears no data has been compromised — at least not yet.

Nick Perrine, a spokesman for the SSA, stated that the agency was "not aware of any compromise to this environment," according to the New York Times.

Perrine also defended the actions taken by DOGE, stating, "S.S.A. stores all personal data in secure environments that have robust safeguards in place to protect vital information. The data referenced in the complaint is stored in a longstanding environment used by S.S.A. and walled off from the internet. High-level career S.S.A. officials have administrative access to this system with oversight by S.S.A.'s information security team."

Perrine added that the agency was and remained "dedicated to protecting sensitive personal data."

Congressional investigations may provide more insight into Borges' complaint.

How to protect your data and identity

In the meantime, it's a good idea to follow best practices for protecting against identity theft. Here are some steps to help you quickly protect your data.

Read More

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.