/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

DHS Secretary Kristi Noem fires 24 FEMA IT staffers, including the CIO and CISO; DHS says they failed security protocols and let hackers access FEMA networks

I thought the whole point of DOGE was to expose our data to everyone.  Just paying customers then?  —  Fuck these amateurs.  —  www.nextgov.com/people/2025/ ... @snacking.dev : The real story isn't the firings here its  —  “uncovered several severe lapses in security that allowed the threat actor to breach FEMA's network and threaten the entire department and the nation as a whole,” DHS said"  —  So FEMAs networks were breached?  Was it disclosed? David DiMolfetta / @ddimolfetta : NEW: Noem terminates 24 FEMA IT staffers after a review found security lapses that let hackers get inside.  An internal email I obtained ordered all agency employees to change their passwords “due to recent cybersecurity incidents and threats.”  —  www.nextgov.com/people/2025/ ... Lesley Carhart / @hacks4pancakes.com : I don't think I'm ready for the $25,000 cybersecurity cosplay tbh.  —  Meanwhile 50% of DHS passwords now contain “August 25” in perpetuity Forums: r/technology : Noem terminates 24 FEMA workers for failing to address cyber vulnerabilities r/politics : Noem terminates 24 FEMA workers for failing to address cyber vulnerabilities

Nextgov/FCW David DiMolfetta

Context & Ripple Effects

The dismissals follow a reported network intrusion and a department-wide instruction for employees to change passwords. FEMA also has a prior record of data-handling failures, including a watchdog finding that it exposed disaster survivors’ information to a contractor in an earlier FEMA privacy lapse.

The episode puts operational weight on FEMA’s security leadership at a time when government cyber teams have faced a persistent shortage of cybersecurity workers. Related coverage later described a widespread incident involving employee data from FEMA and CBP, sharpening the significance of the underlying access failure.

First-order effects

  • FEMA immediately loses 24 IT staff, including its CIO and CISO, while DHS must replace or redistribute responsibility for security governance, incident response, and core IT operations.
  • DHS employees face immediate credential-security measures after the reported incidents, while FEMA’s systems and any potentially affected data require investigation and remediation.

Second-order effects

  • Removing senior security leaders during breach response can slow continuity of remediation unless DHS rapidly assigns clear interim ownership and preserves institutional knowledge.
  • The alleged failure to follow protocols is likely to trigger tighter access reviews, logging, patch-management checks, and oversight across DHS components—not just FEMA.

Third-order effects

  • If agencies respond to cyber failures primarily through abrupt leadership removals, federal cyber resilience will increasingly depend on whether they can retain and rapidly replace scarce security specialists.
  • The pattern points toward more centralized DHS scrutiny of component-agency security controls, with accountability tied more directly to demonstrable control execution after incidents.

The trend: Federal agencies are shifting from treating cybersecurity as a compliance function to treating lapses in operational controls as an immediate leadership-accountability issue.

Discussion

  • @ronfilipkowski Ron Filipkowski on x
    Aside from the constitutional issue of Noem taking $110 million of FEMA money and giving it to churches, it will be interesting to watch how much of this money ends up in people's pockets. [image]
  • @ddimolfetta David DiMolfetta on x
    NEW: Noem terminates 24 FEMA IT staffers after a review found security lapses that let hackers get inside. An internal email I obtained ordered all agency employees to change their passwords “due to recent cybersecurity incidents and threats.” https://www.nextgov.com/...
  • @jonzoidberg.xyz JonZoidberg on bluesky
    Cosplay Noem fired 24 FEMA employees for failing basic security protocols and allowing hackers access.  —  I thought the whole point of DOGE was to expose our data to everyone.  Just paying customers then?  —  Fuck these amateurs.  —  www.nextgov.com/people/2025/ ...
  • @snacking.dev @snacking.dev on bluesky
    The real story isn't the firings here its  —  “uncovered several severe lapses in security that allowed the threat actor to breach FEMA's network and threaten the entire department and the nation as a whole,” DHS said"  —  So FEMAs networks were breached?  Was it disclosed?
  • @ddimolfetta David DiMolfetta on bluesky
    NEW: Noem terminates 24 FEMA IT staffers after a review found security lapses that let hackers get inside.  An internal email I obtained ordered all agency employees to change their passwords “due to recent cybersecurity incidents and threats.”  —  www.nextgov.com/people/2025/ ..…
  • @hacks4pancakes.com Lesley Carhart on bluesky
    I don't think I'm ready for the $25,000 cybersecurity cosplay tbh.  —  Meanwhile 50% of DHS passwords now contain “August 25” in perpetuity
  • r/technology r on reddit
    Noem terminates 24 FEMA workers for failing to address cyber vulnerabilities
  • r/politics r on reddit
    Noem terminates 24 FEMA workers for failing to address cyber vulnerabilities