The Washington Post has published a report detailing a whistleblower complaint alleging that a former Department of Government Efficiency (DOGE) employee stole two complete databases from the U.S. Social Security Administration while employed as a DOGE software engineer.

The databases stolen include the “’Numident’ and the ‘Master Death File,’ which could cover records for more than 500 million living and dead Americans, including Social Security numbers and birth data.”

First of all, how did a software engineer even have access to these databases that contain highly sensitive data, and then have the ability to download massive amounts of data on 500 million individuals to a thumb drive? My head is exploding.

Second, the whistleblower alleges that the software engineer left DOGE in October 2025 to start a new job at a government contractor, “where he told colleagues he ‘possessed two tightly restricted databases of U.S. citizens’ information’ and planned to share that information with his new employer.” If the software engineer did so, not only are both against the law, but are separate unauthorized disclosures that may require notification to every person whose data is contained on those databases. My head is imploding now too.

The Social Security Administration inspector general is allegedly investigating the whistleblower’s complaint, but the allegations are extremely alarming, and an investigation is not sufficient. Who knows how long it will take for the investigation to conclude? Meanwhile, if true, potentially all of our Social Security data on a thumb drive is in the hands of a software engineer, who clearly does not understand the importance and consequences of their actions, and potentially the individual’s new employer. Laws have been passed to protect our Social Security information for a reason. We expect it to be protected and accessed, used, and disclosed in accordance with the law. If true, this situation underscores how important those laws are, and how detrimental it is when they are broken with impunity.

We have previously raised concerns about the Department of Government Efficiency’s (DOGE) access to highly sensitive data, including data at the Social Security Administration, without appropriate security clearances, access controls, and security measures to protect it.

On August 26, 2025, Charles Borges, the chief data officer at the Social Security Administration, filed a whistleblower disclosure, submitted by the Government Accountability Project that confirmed our fears. The disclosure, addressed to the Senate Committee on Homeland Security & Government Affairs, the Senate Committee on Finance, the Acting Special Counsel, the House Committee on Oversight and Government Reform and the House Ways and Means Committee, alleges that DOGE “employees copied ultrasensitive data to a cloud server that does not meet government standards for protecting data privacy.” He further alleges that there are “serious data security lapses…orchestrated by DOGE officials, currently employed as SSA employees, that risk the security of over 300 million Americans’ Social Security data.”

In June 2025, the U.S. Supreme Court stayed the March 2025 preliminary injunction issued by the District Court which blocked DOGE’s access to sensitive government data, allowing DOGE to proceed with its work. The disclosure alleges that, since then, “DOGE officials employed by SSA have created a live copy of a critical database, known as the NUMIDENT file, in a cloud environment.” The NUMIDENT database has over “548 million Social Security numbers, along with the identifying information of everyone living or dead who has ever had a Social Security number.” The database is alleged to include “all information submitted in an application for a United States Social Security card.” (Emphasis original).

According to the complaint, the data hosted on the virtual cloud environment with Amazon Web Services was only accessible by DOGE employees, and DOGE was warned that copying the data “could make Americans vulnerable to identity theft,” but DOGE proceeded with copying the data. In addition, there were “no oversight mechanisms in place to determine what the data was being used for or whether it was properly secured, and there was no independent security monitoring of the cloud environment,” and the Social Security Administration’s acting chief information security officer warned that “after a thorough review, we have determined that this request [to copy the information] poses a high risk.” The disclosure further states that “no one outside the former DOGE group had insight into code being executed against SSA’s live production data.” To this writer, this also could mean that the data could be disclosed from the environment, including into generative AI tools, which is of grave concern.

According to the claimed whistleblower, “should bad actors gain access to this cloud environment, Americans may be susceptible to widespread identity theft, may lose vital health care and food benefits, and the government may be responsible for reissuing every American a new Social Security number at great cost.” This disclosure is distressing. Copying the entire database that contains highly sensitive data of everyone who has submitted an application for a U.S. Social Security card into an insecure environment, with no outside controls or using best practices, is a recipe for disaster. Since the U.S. Supreme Court has failed to acknowledge the risk of unfettered access to the Social Security Administration’s data, hopefully, members of Congress will urgently address this disclosure with deliberate speed to minimize the risk to all of us.

On April 21, 2025, the Oregon Department of Justice’s Privacy Unit reported a “big spike” in complaints about the Department of Government Efficiency (DOGE) in the first quarter of 2025.

The report stated, “Specifically, Oregonians are concerned about how government entities are handling their personal information. As of March 31, 2025, the unit had received more than 250 complaints about DOGE.”

The Oregon Department of Justice has joined other Attorneys General to file suit against the administration, requesting limitations on DOGE’s access to Americans’ personal information, and a court issued an order blocking DOGE’s access to Treasury Department information. Oregonians are not alone in their concern about DOGE’s vast and unrestricted access to personal information. Many states have consumer protection divisions that allow consumers to issue complaints about privacy protections.

If you are concerned about unrestricted access to your personal information by federal government and/or DOGE representatives, consider contacting your state consumer protection division so your voice is heard.

Becker’s Hospital Review reports that the Department of Government Efficiency (DOGE) “has access to sensitive information in 19 HHS databases and systems,” according to a court filing obtained by Wired. HHS provided the information during the discovery process in the lawsuit filed by the American Federation of Labor and Congress of Industrial Organizations against the federal government, requesting restriction of DOGE’s access to federal systems.

According to Becker’s, DOGE had not previously disclosed nine of the 19 systems, which “contain various protected health information, ranging from email and mailing addresses to Social Security numbers and medical notes.”

Some of the systems included federal employees’ data and access to Medicare recipients’ personal information. For instance, one system listed is the Integrated Data Repository Cloud system, which “stores and integrates Medicare claims data with beneficiary and provider data sources.” Other listed systems include the NIH Workforce Analytics Workbench, which “tracks current and historical data on the NIH workforce, including headcounts and retirement information,” the Office of Human Resources Enterprise Human Capital Management Investment system, which “manages personnel actions and employee benefits at HHS,” and the Business Intelligence Information System, which “stores cloud-based HHS human resources and payroll data for analysis and reporting.”

We will continue to follow courts’ analyses and decisions relating to DOGE’s access to sensitive federal employees and individual data.

On February 21, 2025, a federal district court judge from the Southern District of New York issued a preliminary injunction against the Department of Government Efficiency’s (DOGE), access to Treasury Department payment systems, stating access was provided in a “chaotic and haphazard manner.” The order resulted from a suit filed by 19 state Attorneys General against DOGE for unauthorized access to Americans’ data. It prevents anyone affiliated with DOGE from accessing federal payment systems until further order.

According to the 64-page opinion, the judge was critical of the “‘rushed’ process by DOGE to access Bureau of Fiscal Service’s payment systems, which stores the names, Social Security numbers, birth dates, birth places, home addresses and telephone numbers, email addresses, and bank account information of Americans who have transacted with the federal government.”

The District Court also noted that “[t]he record is silent as to what vetting or security clearance process they went through prior to their appointment” and reported being “troubled by the fact that Elez [a DOGE associate] was apparently granted full access to [Bureau of Fiscal Service] systems rather than read-only access, writing that that process was ‘rushed and undertaken under political pressure.’” We have made a similar observation.

The Court requested that the Treasury Department provide a report by March 24, 2025: (1) certifying that the DOGE associates have been vetted, have obtained proper security clearances, and have been properly trained; and (2) setting forth the mitigation measures which have been taken to minimize threats associated with the access, including the reporting chains for DOGE within the Treasury Department. 

The ruling stated that “[t]he process by which the Treasury DOGE Team was appointed, brought on board, and provided with access to [Bureau of the Fiscal Service] payment systems could have been implemented in a measured, reasonable, and thoughtful way. To date, based on the record currently before the Court, it does not appear that this has been the case.”

The Department of Government Efficiency’s (DOGE) staggering unfettered access to all Americans’ personal information is highly concerning. DOGE employees’ access includes databases at the Office of Personnel Management, the Department of Education, the Department of Health and Human Services, and the U.S. Treasury.

If you want more information about the DOGE employees who have access to this highly sensitive data, Wired and KrebsOnSecurity have provided fascinating but disturbing accounts.

Meanwhile, New York and other states have filed suit against DOGE, alleging that the unfettered access to the federal databases is a privacy violation. On February 14, 2025, a New York federal judge found “good cause to extend a temporary restraining order” stopping DOGE employees from accessing U.S. Treasury Department databases. However, the next day, another federal judge in Washington, D.C., denied a request to stop DOGE from accessing the databases of the Department of Labor, the Department of Health and Human Services, and the Consumer Financial Protection Bureau. That means that DOGE employees now have access to the sensitive health and claims information of Medicare recipients, as well as the identities of individuals who have made workplace health and safety complaints. NBC News has reported that “the Labor Department authorized DOGE employees to use software to remotely transfer large data sets.”

Currently, 11 lawsuits have been filed against DOGE over access to sensitive information in federal databases, alleging that the access violates privacy laws. The databases include student loan applications at the Department of Education, taxpayer information at the Department of the Treasury, and the personnel records of all federal employees contained in the database of the Office of Personnel Management, the Department of Labor, the Social Security Administration, FEMA, and USAID.

According to a plaintiff, the potential to misuse Americans’ personally identifiable information “is serious and irrevocable….The risks are staggering: identity theft, fraud, and political targeting. Once your data is exposed, it’s virtually impossible to undo the damage.” We will be closely watching the progress of these suits and urge you to stay informed as we offer insight on their impact to the protection of our personal information.

According to a highly critical article recently published by TechCrunch,  the Department of Government Efficiency (DOGE), President Trump’s advisory board headed by Elon Musk, has “taken control of top federal departments and datasets” and has access to “sensitive data of millions of Americans and the nation’s closest allies.” The author calls this “the biggest breach of US government data.” He continues, “[w]hether a feat or a coup (which depends entirely on your point of view), a small group of mostly young, private-sector employees from Musk’s businesses and associates — many with no prior government experience — can now view and, in some cases, control the federal government’s most sensitive data on millions of Americans and our closest allies.”

According to USA Today, “The amount of sensitive data that Musk and his team could access is so vast it has historically been off limits to all but a handful of career civil servants.” The article points out that:

If you received a tax refund, Elon Musk could get your Social Security number and even your bank account and routing numbers. Paying off a student loan or a government-backed mortgage? Musk and his aides could dig through that data, too.

If you get a monthly Social Security check, receive Medicaid or other government benefits like SNAP (formerly known as food stamps), or work for the federal government, all of your personal information would be at the Musk team’s fingertips. The same holds true if you’ve been awarded a federal contract or grant.

Private medical history could potentially fall under the scrutiny of Musk and his assistants if your doctor or dentist provides that level of detail to the government when requesting Medicaid reimbursement for the cost of your care.

A federal judge in New York recently issued a preliminary injunction stopping Musk and his software engineers from accessing the data, despite Musk calling the judge “corrupt” on X. USA Today reports that the White House says Musk and his engineers only have “read-only” access to the data, but that is not very comforting from a security standpoint. The Treasury Department has reportedly admitted that one DOGE staffer, a 25-year-old software engineer, had been mistakenly granted “read/write” permission on February 5, 2025. That is just frightening to me as one who works hard to protects my personal information.

Tech Crunch reported that data security is not a priority for DOGE.

“For example, a DOGE staffer reportedly used a personal Gmail account to access a government call, and a newly filed lawsuit by federal whistleblowers claims DOGE ordered an unauthorized email server to be connected to the government network, which violates federal privacy law. DOGE staffers are also said to be feeding sensitive data from at least one government department into AI software.”

We all know that Musk loves AI. We are also well aware of the risks of using AI with highly sensitive data, including unauthorized disclosure and the ability to include it in outputs.

All of this has prompted questions about whether this advisory board has proper security clearance to access our data.

Should you be concerned? Absolutely. I understand the goal of cutting costs. But why do these employees have access to our most private information, including our full Social Security numbers and health information? Do they really need that specific data to determine fraud or overspending?

I argue no. A tenet of data security is proper access controls, only having access to the data needed for business purposes. DOGE’s unfettered access to our highly sensitive information is not limited to only data needed for a specific purpose. The security procedures for accessing the data are in question, and proper security protocols must be followed. According to Senator Ron Wyden of Oregon and Senator Jon Ossoff  of Georgia, who is a member of the U.S. Senate Intelligence Committee, this is “a national security risk.” As a privacy and cybersecurity lawyer, I am very concerned. A hearing on an early lawsuit filed to prohibit this unrestricted access is scheduled for tomorrow. We will keep you apprised of developments as they progress.

I apologize that this post is not light reading. It’s critically important to know what the threats are so you can avoid becoming a victim.

Although disconcerting, it is crucial to know what has happened in the first half of this year. TechCrunch recently issued a report outlining the worst breaches of 2026—so far:

  • DOGE’s massive swipe of Social Security data (I’ve discussed this  in numerous posts)
  • Hackers increased targeting of water systems and energy grids (discussed here)
  • Iranian government hackers attacking Stryker with a destructive device hack (ditto)
  • ShinyHunters’ disruptive hacking campaign against Instructure, among other targets (ShinyHunters has been a frequent subject of our posts)
  • The supply chain under attack, targeting open-source projects and big tech companies
  • FBI’s surveillance system breach, sparking a “major cyber incident“
  • Hasbro’s hack leading to weeks of downtime
  • Exposure of millions of passports and driver licenses

What can we learn from these trends?

According to TechCrunch, “the attacks are getting bolder, more destructive, and harder to contain.” The trends confirm that as technology advances, so must defenses equally. Cybersecurity measures must be sophisticated enough to block attackers so they will move on to the next victim. A mature cybersecurity posture, both personally and professionally, must be a priority to prevent becoming victimized. In a world of geopolitical discontent, cyber attackers serve as warriors for nation states, and at the same time, our own government is failing to protect our data and our warriors’ data. Unfortunately, the Cybersecurity and Infrastructure Security Agency’s funding has been decimated, so we are left to our own devices (pardon the pun).

We need to take greater responsibility for protecting our own information while demanding stronger safeguards from our government, especially for the sensitive data of current and veteran military personnel. Additionally, private companies must also do more to prevent exposure. Robust cybersecurity programs across individuals, government, and the private sector are essential. This is no longer a future concern; it is reality. Without collective action, the second half of 2026 will bring more of the same.

On February 5, 2026, a Massachusetts federal judge issued an order staying information-sharing between the IRS and ICE, as well as  a preliminary injunction prohibiting Kristi Noem, Secretary of the Department of Homeland Security, ICE, acting-Director Todd Lyons, and any DHS and ICE agent from “inspecting, viewing, using, copying, distributing, relying on, or otherwise acting upon any return information that had been obtained from or disclosed by the IRS” through a Memorandum of Understanding (MOU) that was signed between the two agencies on April 7, 2025. The MOU was designed with the purpose of “sharing of tax information across agencies to implement President Trump’s direction that DHS ‘take immediate steps to identify, exclude, or remove aliens illegally present in the United States.’”

In addition, the court found that the storage of the taxpayer data on an unnamed ICE employee’s computer, “constitutes impermissible storage” of the data “in contravention” of the Internal Revenue Code. The court ordered that the defendants provide a copy of the order to the employee “whose government-issued computer holds the information received from the IRS on August 7, 2025,” and required that ICE confirm that the order was delivered to that individual by February 10, 2026. The court held that “Plaintiffs have established a high likelihood that ICE’s handling, use, and storage of taxpayer addresses violated and continues to violate” the Internal Revenue Code.

The facts behind the lawsuit are that following the execution of the MOU between the IRS and ICE, ICE requested the data of almost 1.3 million taxpayers on August 6, 2025, and the IRS provided taxpayer information of 47,000 individuals that matched the ICE request on August 7, 2025. That data has been stored and used by ICE since August 7, 2025.

The court stated that the disclosure of taxpayer data from the IRS to ICE was contrary to Section 6103 of the Internal Revenue Code which “strictly prohibits the disclosure” of taxpayer data to government agencies, private entities, or citizens, which taxpayers rely upon when filing their taxes. The court further noted that “the Internal Revenue Code provides strong privacy protections for information submitted by taxpayers and/or obtained by the IRS.”

The court found that the plaintiffs sufficiently demonstrated irreparable harm and that they have “been and will continue to be harmed by the data-sharing due to the erosion of trust between the organizations and their members.”

We have outlined numerous privacy concerns about how taxpayer and other data have been shared between federal agencies in this administration, including the actions of the Department of Government Efficiency a/k/a DOGE.. These issues will continue to be litigated, and we will update you on court rulings as they progress.

Happy New Year! 2025 was a busy year for the Insider authors—we published 271 posts throughout 2025. To kick-off 2026, in case you missed them last year, we are providing the articles from 2025 that were the most interesting to our readers across various categories.

We hope you enjoy them and look forward to another productive year of keeping our readers informed on the rapidly changing and dynamic areas of data privacy, cybersecurity, information governance, artificial intelligence, and of course—the weekly Privacy Tip!

CYBERSECURITY

FBI Warns of Account Takeover Fraud

Insider Threats Climb + Are Costly

ENFORCEMENT + LITIGATION

EdTech and Privacy of Student Information: A Case Study

Breaches Within Breaches: Contractual Obligations After a Security Incident

DATA PRIVACY

Privacy Under Pressure: What the NYT v. OpenAI Teaches Us About Data Governance

New State Privacy Laws Expand Consumer Data Control in 2026

INFORMATION GOVERNANCE

Why Dumping Sensitive Data on Network Shares is a Liability

ARTIFICAL INTELLIGENCE

When AI Notetakers Take the Stand: The Legal Risks Lurking in Your Virtual Meetings

PRIVACY TIPS

Privacy Tip #431 – DOGE Has Access to Our Personal Information: What You Need to Know

Privacy Tip #7 – Who is listening to your conversations through your smartphone microphone?