Court filings in ongoing litigation over the Department of Government Efficiency (DOGE) access to Social Security Administration (SSA) data describe a March 2025 outreach from a political advocacy group seeking help analyzing state voter rolls it had obtained, with the stated goal of finding voter fraud and overturning election results in certain states. According to a Justice Department correction signed by civil division official Elizabeth Shapiro, two DOGE associates at SSA were contacted, and one signed and sent a “Voter Data Agreement” that was not processed through SSA’s normal data-exchange approval procedures; SSA later discovered the agreement during an unrelated internal review.
The filings say SSA has not seen evidence that SSA data were actually shared with the advocacy group, but communications suggest DOGE team members could have been asked to access SSA data to match against voter rolls, potentially involving Social Security numbers and use of unapproved third-party infrastructure. SSA made referrals to the Office of Special Counsel for potential Hatch Act violations tied to the alleged political activity, while the broader dispute over DOGE’s access to SSA data continues and has prompted corrections to prior SSA testimony in court.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-10, the U.S. Court of Appeals for the Fourth Circuit vacated the lower court order that had restricted DOGE access to sensitive SSA systems, ruling plaintiffs had not shown likely irreparable harm on the record before the district court. The appellate decision acknowledged later revelations about possible improper data access as alarming and sent the case back for further proceedings.
On 2026-01-20, court-filed corrections to earlier testimony by senior SSA officials disclosed that two DOGE members may have improperly accessed and potentially shared sensitive SSA data in connection with the advocacy group's election-related project. The filing also described an encrypted file believed derived from SSA records being emailed externally and raised concerns about data handling on third-party infrastructure.
After reviewing the conduct, the Social Security Administration made two Hatch Act referrals involving DOGE officials connected to the voter-roll analysis effort and the unapproved data-sharing agreement. The referrals were based on concerns that SSA data may have been used for political activity.
At a later point in the litigation over DOGE's SSA access, a federal judge issued a temporary restraining order blocking DOGE members from accessing SSA systems containing Social Security numbers, medical records, tax information, driver's license numbers, and other sensitive personal data. Subsequent filings alleged DOGE associates may still have retained or accessed sensitive data after that order.
Around March 2025, DOGE personnel at SSA were alleged to have accessed sensitive SSA data, potentially matched it against voter rolls, and used unapproved third-party infrastructure such as Cloudflare links and external servers to share or process data. SSA later said it could not determine what data may have been shared or whether any remained on third-party systems.
On 2025-03-24, a DOGE employee embedded at the Social Security Administration reportedly signed and sent a "Voter Data Agreement" tied to a political advocacy group's request to analyze acquired state voter rolls for evidence of voter fraud. Court filings say the effort was aimed at supporting attempts to overturn election results in certain states.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
nextgov.com
Open sourcescworld.com
Open sourcenextgov.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.