DHS Secretary Kristi Noem fires 24 FEMA IT staffers, including the CIO and CISO; DHS says they failed security protocols and let hackers access FEMA networks
I thought the whole point of DOGE was to expose our data to everyone. Just paying customers then? — Fuck these amateurs. — www.nextgov.com/people/2025/ ... @snacking.dev : The real story isn't the firings here its — “uncovered several severe lapses in security that allowed the threat actor to breach FEMA's network and threaten the entire department and the nation as a whole,” DHS said" — So FEMAs networks were breached? Was it disclosed? David DiMolfetta / @ddimolfetta : NEW: Noem terminates 24 FEMA IT staffers after a review found security lapses that let hackers get inside. An internal email I obtained ordered all agency employees to change their passwords “due to recent cybersecurity incidents and threats.” — www.nextgov.com/people/2025/ ... Lesley Carhart / @hacks4pancakes.com : I don't think I'm ready for the $25,000 cybersecurity cosplay tbh. — Meanwhile 50% of DHS passwords now contain “August 25” in perpetuity Forums: r/technology : Noem terminates 24 FEMA workers for failing to address cyber vulnerabilities r/politics : Noem terminates 24 FEMA workers for failing to address cyber vulnerabilities
Context & Ripple Effects
The dismissals follow a reported network intrusion and a department-wide instruction for employees to change passwords. FEMA also has a prior record of data-handling failures, including a watchdog finding that it exposed disaster survivors’ information to a contractor in an earlier FEMA privacy lapse.
The episode puts operational weight on FEMA’s security leadership at a time when government cyber teams have faced a persistent shortage of cybersecurity workers. Related coverage later described a widespread incident involving employee data from FEMA and CBP, sharpening the significance of the underlying access failure.
First-order effects
- FEMA immediately loses 24 IT staff, including its CIO and CISO, while DHS must replace or redistribute responsibility for security governance, incident response, and core IT operations.
- DHS employees face immediate credential-security measures after the reported incidents, while FEMA’s systems and any potentially affected data require investigation and remediation.
Second-order effects
- Removing senior security leaders during breach response can slow continuity of remediation unless DHS rapidly assigns clear interim ownership and preserves institutional knowledge.
- The alleged failure to follow protocols is likely to trigger tighter access reviews, logging, patch-management checks, and oversight across DHS components—not just FEMA.
Third-order effects
- If agencies respond to cyber failures primarily through abrupt leadership removals, federal cyber resilience will increasingly depend on whether they can retain and rapidly replace scarce security specialists.
- The pattern points toward more centralized DHS scrutiny of component-agency security controls, with accountability tied more directly to demonstrable control execution after incidents.
The trend: Federal agencies are shifting from treating cybersecurity as a compliance function to treating lapses in operational controls as an immediate leadership-accountability issue.