Tech Souls, Connected.

DOGE Operatives Gave Themselves Access to Live SSN Data, Whistleblower Warns

Sensitive personal records for hundreds of millions of Americans allegedly exposed in risky cloud migration approved by DOGE operatives


Whistleblower Sounds Alarm on Data Security Breach

A high-ranking Social Security Administration official has filed a whistleblower complaint accusing Trump-era appointees of moving live copies of Americans’ Social Security records to an insecure cloud server, risking one of the largest potential data exposures in U.S. government history.

  • Charles Borges, the agency’s Chief Data Officer, claims officials from the Department of Government Efficiency (DOGE) bypassed oversight protocols to upload the data in June.
  • The sensitive database, known as NUMIDENT (Numerical Identification System), includes over 450 million records containing names, birthplaces, citizenship, SSNs of family members, health data, income, and other personally identifiable information (PII).

“It is possible that the sensitive PII on every American… could be exposed publicly, and shared widely,” Borges warned.


Who Is DOGE — and What Did They Do?

DOGE, a team of former Elon Musk associates brought into government under the Trump administration to “cut waste,” has taken sweeping control of datasets across federal agencies since January.

  • Borges says DOGE operatives, acting under the guise of modernization, moved Social Security’s most critical data to a cloud server hosted on Amazon Web Services (AWS) — without standard security controls or clear audit trails.
  • By becoming cloud administrators, DOGE staff allegedly gained the power to create publicly accessible endpoints, theoretically exposing Social Security data to anyone with access.

“The business need is higher than the security risk,” said Aram Moghaddassi, the SSA’s CIO, who approved the move despite warnings.


Court Battles and Internal Pushback

Though a federal restraining order in March temporarily blocked DOGE access to the database, the U.S. Supreme Court lifted the order on June 6.

  • Within days, DOGE began pushing for internal approval.
  • Borges raised concerns but says his objections were overruled by Moghaddassi and Michael Russo, a senior DOGE operative and former SSA CIO.
  • Russo had previously helped expand DOGE’s control over agency systems and reportedly supported the cloud migration.

Borges’ complaint, made public via the Government Accountability Project, alleges the move violated federal privacy laws and internal security controls.

  • Uploading live data without proper oversight risks a catastrophic breach.
  • The worst-case scenario? The need to reissue every American’s Social Security number.

The complaint calls for urgent Congressional oversight, arguing that existing safeguards were knowingly bypassed in favor of speed and political pressure.


Official Responses: Reassurances and Deflections

A White House spokesperson declined to comment, referring inquiries to the Social Security Administration (SSA).

In a statement, SSA spokesperson Nick Perrine said:

“The data referenced… is stored in a long-standing environment used by SSA and walled off from the internet… High-level career SSA officials have administrative access to this system.”

He added that the agency is “not aware of any compromise”, but did not address whether the current cloud environment meets federal compliance standards or whether DOGE has retained access.


Context: Federal Data Risks Are Rare — But Real

While federal cloud data breaches are uncommon, misconfigurations have caused damage before.

  • In 2023, the Department of Defense accidentally left thousands of sensitive military emails publicly exposed on Microsoft Azure, due to a permissions error.
  • That incident underscores how cloud environments — even in government settings — are not immune to configuration or oversight failures.

What’s Next?

The whistleblower complaint is expected to trigger Congressional hearings and further scrutiny of the DOGE team’s role in federal IT operations.

If verified, the allegations may force:

  • DOJ investigations into data privacy violations
  • A reevaluation of cloud migration protocols for sensitive federal data
  • Potential reform in federal cybersecurity standards and contractor oversight

Share this article
Shareable URL
Prev Post

Carbon Offsets Under Fire: Apple Watch Marketing Hits Legal Roadblock

Next Post

Inspiration or Intrusion? Libby’s AI Feature Divides Users

Read next