WOODLAWN, MARYLAND - MARCH 19: A sign in front of the entrance of the Security Administration's main campus on March 19, 2025 in Woodlawn, Maryland. Elon Musk's Department of Government Efficiency (DOGE) has announced plans to eliminate thousands of agency positions as well as numerous regional and local Social Security offices. (Photo by Kayla Bartkowski/Getty Images)

Washington D.C. – A bombshell complaint filed by a federal whistleblower reveals that the Social Security Administration (SSA) has placed the highly sensitive personal data of over 300 million Americans – including Social Security numbers, names, and birthdates – onto a private, inadequately secured server. The allegations, made by the SSA’s own Chief Data Officer, warn of a “catastrophic” potential for identity theft and have led to internal discussions about the unprecedented step of re-issuing Social Security numbers to millions.

Charles Borges, the chief data officer at the Social Security Administration, has formally accused senior officials—all recent appointees from the former Department of Government Efficiency (DOGE) team—of orchestrating the unauthorized copying of this vast dataset. Filed through the non-profit Government Accountability Project, Borges’ complaint asserts that these actions “constitute violations of laws, rules and regulations, abuse of authority, gross mismanagement, and creation of a substantial and specific threat to public health and safety.”

According to the complaint, the copied information resides on a server accessible by other former DOGE employees within the SSA, yet it alarmingly lacks the robust security protocols typically safeguarding the agency’s data. Career cybersecurity officials within the SSA reportedly characterized the decision to duplicate the data as “very high risk,” acknowledging the grim possibility of mass re-issuance of Social Security numbers if the cloud server were compromised.

Andrea Meza, an attorney with the Government Accountability Project representing Borges, voiced profound concern: “This cloud environment, seemingly established for DOGE-affiliated Social Security staffers, critically lacks independent security, monitoring, and oversight. Mr. Borges has serious concerns about the vulnerability it causes for nearly every American’s data.”

For its part, the Social Security Administration issued a statement claiming its data remains secure. “The data referenced in the complaint is stored in a long-standing environment used by SSA and walled off from the internet,” the statement declared. “We are not aware of any compromise to this environment and remain dedicated to protecting sensitive personal data.”

However, Borges’ allegations are not isolated. This incident marks the latest in a troubling pattern where DOGE and Trump administration officials have been accused of disregarding privacy protections for sensitive personal information. Previous reports include a whistleblower claiming DOGE officials took sensitive data from the National Labor Relations Board and attempted to conceal their tracks, alongside apparent efforts by DOGE officials at the SSA to exploit personal data to advance unsubstantiated claims of voter fraud.

The critical data transfer occurred in the immediate aftermath of a contentious 6-3 U.S. Supreme Court ruling in June, which temporarily lifted a restraining order and granted DOGE team members access to the SSA’s most sensitive information.

Internal Warnings Ignored

Days after the Supreme Court’s decision, on June 10, John Solly, a former DOGE employee now at the SSA, initiated the request to duplicate the agency’s Numerical Identification System (NUMIDENT) database. The NUMIDENT, the master file for all Social Security card applications, contains comprehensive details including applicants’ names, place and date of birth, citizenship, race and ethnicity, parents’ names – along with the Social Security numbers themselves.

This request, as outlined in the complaint, effectively created an independent copy of the database, granting former DOGE officials “unfettered access.”

Internal warnings from SSA career cybersecurity professionals were stark. A “Risk Assessment Form” dated June 16, reviewed by NPR, unequivocally stated: “Unauthorized access to the NUMIDENT would be considered catastrophic impact to SSA beneficiaries and SSA programs.” The assessment explicitly recommended against using “production data.”

Despite these dire warnings, the data transfer proceeded in late June, after Solly’s request received approval from Michael Russo, another DOGE-affiliated official. By July, Aram Moghaddassi, the SSA’s chief information officer – also a former DOGE member – authorized a “Provisional Authorization to Operate.” This effectively greenlit officials to work with the duplicated data.

Moghaddassi’s authorization, also seen by NPR, concluded with a chilling declaration: “I have determined the business need is higher than the security risk associated with this implementation and I accept all risks associated with this implementation and operation.”

The Social Security Administration maintains that the data copy remains within its secure environment, stating, “High-level career SSA officials have administrative access to this system with oversight by SSA’s Information Security team.”

This developing story was first reported by NPR News.

Leave a Reply

Discover more from The Buzz-Report

Subscribe now to keep reading and get access to the full archive.

Continue reading