SSA's chief data officer files a whistleblower complaint that DOGE uploaded a database with every Social Security number ever issued to an insecure cloud server
DOGE team members uploaded a database with the personal information of hundreds of millions of Americans to a vulnerable cloud server …
New York TimesNicholas Nehamas
Context & Ripple Effects
The complaint sits within a broader dispute over DOGE’s handling of federal personal data. Earlier reporting said DOGE planned a centralized repository of residents’ information despite security-protocol concerns, raising the stakes of moving Social Security records into cloud infrastructure.
The allegations later gained added relevance as the DOJ said DOGE staff accessed Social Security data restricted by a court ruling and shared agency data on third-party servers, while the inspector general examined claims involving an ex-DOGE engineer’s handling of sensitive data.
First-order effects
SSA’s chief data officer has formally placed the alleged cloud upload into a whistleblower process, putting the agency’s data controls and DOGE’s access practices under immediate scrutiny.
If the complaint is substantiated, hundreds of millions of Americans’ identifying information may have been exposed to a vulnerable environment, requiring SSA to assess access, containment, and notification obligations.
Second-order effects
The allegation increases pressure on SSA and other agencies to restrict privileged access, document data transfers, and reassess use of third-party cloud services by DOGE personnel.
It strengthens the significance of the later [[a:1161801|DOJ account of restricted Social Security data being accessed and shared on third-party servers]], making oversight bodies more likely to examine whether access rules were enforceable in practice.
Third-order effects
The episode points to a durable governance conflict: centralizing government data can expand operational reach, but also concentrates privacy and security risk unless permission boundaries, audit trails, and independent controls keep pace.
If similar allegations recur, federal modernization efforts may face more formal limits on cross-agency data consolidation and on staff moving sensitive datasets between government and external systems.
The trend: This is one data point in the tightening public-data permission boundary around efforts to consolidate and operationalize sensitive government records.
sure, the Chinese hacked our telecoms, data brokers sold info on our every movement to randos, Russian criminal gangs compromised our court system, and weird fascist incels posted grandma's social security # unencrypted to the cloud, but at least we had a pointless four year deba…
DOGE put at risk *every person with a Social Security Number* for identify theft. — DOGE's treatment of these data is extraordinary-the level of protection that has long been applied to these data is rigid. But they just uploaded it all to the cloud! www.nytimes.com/2025/08/26…
Another reminder that “trust me” just isn't good enough for the privacy and security of your personal information. We need strong legal and technical requirements for privacy and for security of personal data, with heavy penalties for those who violate our trust. www.nytimes.com…
I hate to say I told you so but...centralizing government data infrastructures and turning them over to inexperiences actors generates big risks to society. We are starting to see the first consequences for social security. Others will follow. — www.nytimes.com/2025/08/26/u..…
Did DOGE create the copy as a DOGE (White House) database or an embedded-in-agency-DOGE team database? Whose record is it - the agency's or the White House's? — www.nytimes.com/2025/08/26/u...
I can think of a nation-state adversary or two that has already conducted oversight audits for us. — “But his disclosure stated that as of late June, ‘no verified audit or oversight mechanisms’ existed to monitor what DOGE was using the data for or whether it was being shared o…
DOGE made their own copy of basically all Social Security data and won't tell anyone how/if it is secured and who they are sharing it with. Remember that Big Balls has a history of working with Cyber criminals on Telegram. www.nytimes.com/2025/08/26/u...