{"id":6455,"date":"2025-08-27T10:03:29","date_gmt":"2025-08-27T10:03:29","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/27\/doge-accused-of-creating-live-copy-of-the-countrys-social-security-information-in-unsecured-cloud-environment\/"},"modified":"2025-08-27T10:03:29","modified_gmt":"2025-08-27T10:03:29","slug":"doge-accused-of-creating-live-copy-of-the-countrys-social-security-information-in-unsecured-cloud-environment","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/27\/doge-accused-of-creating-live-copy-of-the-countrys-social-security-information-in-unsecured-cloud-environment\/","title":{"rendered":"DOGE Accused of Creating Live Copy of the Country\u2019s Social Security Information in Unsecured Cloud Environment"},"content":{"rendered":"<p>    DOGE Accused of Creating Live Copy of the Country\u2019s Social Security Information in Unsecured Cloud Environment<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A whistleblower disclosure filed today alleges that the Department of Government Efficiency (DOGE) within the Social Security Administration (SSA) covertly created a live copy of the nation\u2019s entire Social Security dataset in an unsecured<a href=\"https:\/\/cybersecuritynews.com\/google-cloud-and-cloudflare-outages\/\" target=\"_blank\" rel=\"noreferrer noopener\"> cloud environment<\/a>.\u00a0<\/p>\n<p>Chief Data Officer Charles Borges warned that, if malicious actors gain access, over 300 million Americans could face identity theft, loss of critical benefits, and the monumental task of re-issuing every Social Security number.<\/p>\n<pre class=\"wp-block-preformatted\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Key Takeaways<\/mark><\/strong><br>1. DOGE copied 300M SSNs into an unsecured AWS cloud.<br>2. An automated ETL pipeline synced live SSN data despite a court order.<br>3. The lapse risks mass identity theft and demands zero-trust security.<\/pre>\n<h2 class=\"wp-block-heading\" id=\"h-allegations-of-unsecured-cloud-storage\"><strong>Allegations of Unsecured Cloud Storage<\/strong><\/h2>\n<p><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">According to the protected disclosure\u00a0<a href=\"https:\/\/whistleblower.org\/press-release\/whistleblower-warns-of-possible-risks-to-americans-social-security-information\/\" target=\"_blank\" rel=\"noopener\">submitted<\/a>\u00a0to the U.S. Office of Special Counsel, DOGE officials\u00a0<a href=\"https:\/\/cybersecuritynews.com\/vtenext-vulnerabilities\/\" target=\"_blank\" rel=\"noopener\">bypassed\u00a0<\/a>standard Information Security and Compliance (ISC) controls,<\/span> including encryption-at-rest, role-based access control (RBAC), and continuous audit logging, when provisioning a cloud instance containing live Social Security Number (SSN) records.\u00a0<\/p>\n<p>Borges notes that neither independent vulnerability assessments nor penetration tests were conducted before spinning up the Amazon Web Services (AWS) S3 bucket storing PII, nor were strict Identity and Access Management (IAM) policies enforced.\u00a0<\/p>\n<p>The cloud environment lacked <a href=\"https:\/\/cybersecuritynews.com\/microsoft-multi-factor-authentication-issue\/\">multi-factor <\/a><a href=\"https:\/\/cybersecuritynews.com\/microsoft-multi-factor-authentication-issue\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication <\/a><a href=\"https:\/\/cybersecuritynews.com\/microsoft-multi-factor-authentication-issue\/\">(MFA)<\/a> on API endpoints and did not employ a secure key management service (KMS), rendering the SSN repository vulnerable to credential stuffing or API key leakage.<\/p>\n<p>Court records show that a lawsuit filed in March 2025 resulted in a temporary restraining order preventing DOGE from accessing production SSN systems until June 6, 2025.\u00a0<\/p>\n<p>However, internal logs reviewed by Borges indicate that DOGE engineers continued to synchronize data via an automated ETL pipeline\u2014using Python scripts and the SSA\u2019s internal RESTful APIs, effectively cloning the live database outside SSA\u2019s Security Operations Center (SOC).<\/p>\n<p>Borges claims that DOGE\u2019s actions constitute serious mismanagement and abuse of authority by bypassing the SSA\u2019s Change Management Board (CMB) and violating federal Cloud Security advice (NIST SP 800-144).\u00a0\u00a0<\/p>\n<p>\u201cThis operation not only breaches the Privacy Act but also exposes the public to a significant cyber-attack surface,\u201d Borges wrote in his internal memo.\u00a0<\/p>\n<p>One SSA executive reportedly acknowledged the risk, stating that the agency might need to re-issue SSNs en masse should the data be compromised.<\/p>\n<p>Andrea Meza, counsel for the whistleblower, urged Congress and the Office of Special Counsel to launch immediate oversight.\u00a0<\/p>\n<p>She emphasized that mitigation measures such as enforcing zero-trust architecture, rotating access keys, and deploying real-time intrusion detection systems (IDS) must be implemented without delay to protect Americans\u2019 most sensitive identifiers.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/doge-accused-of-copying-social-security-information\/\">DOGE Accused of Creating Live Copy of the Country\u2019s Social Security Information in Unsecured Cloud Environment<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/doge-accused-of-copying-social-security-information\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>DOGE Accused of Creating Live Copy of the Country\u2019s Social Security Information in Unsecured Cloud Environment A whistleblower disclosure filed today alleges that the Department of Government Efficiency (DOGE) within the Social Security Administration (SSA) covertly created a live copy of the nation\u2019s entire Social Security dataset in an unsecured cloud environment.\u00a0 Chief Data Officer [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-6455","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6455"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6455"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6455\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6455"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6455"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6455"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}