Madhu Gottumukkala, the acting director of the Cybersecurity and Infrastructure Security Agency (CISA), uploaded sensitive U.S. government contracting documents marked “for official use only” into a publicly accessible version of ChatGPT, according to reporting citing multiple Department of Homeland Security (DHS) officials. Although the materials were not classified, CISA cybersecurity sensors detected the activity in August and generated multiple automated alerts intended to prevent data loss or mishandling, prompting a DHS-level internal review to assess potential exposure and impact; the outcome of that review has not been made public.
CISA’s public affairs office said Gottumukkala had been granted a temporary, authorized exception to use ChatGPT “with DHS controls in place,” describing the use as short-term and limited, while also disputing aspects of the reported timeline (stating his last use was in mid-July 2025 and that ChatGPT remains blocked by default unless an exception is granted). The incident highlights the risk that content entered into a public AI service may be shared with the service provider and potentially used to improve responses for other users, contrasting with DHS-approved internal tools (e.g., DHSChat) designed to keep inputs within federal networks.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
CISA issued new insider-threat guidance for critical infrastructure and government organizations, recommending multidisciplinary teams and mitigation measures. The release drew attention because it followed reporting about Gottumukkala's ChatGPT handling of sensitive documents.
Politico reported that CISA's acting director had uploaded sensitive government documents to a public ChatGPT instance, bringing the previously undisclosed incident into public view.
Senior DHS officials, including legal and CIO leadership, reviewed what had been uploaded and assessed possible harm to government security and whether policy had been followed. The matter escalated to a DHS-level review.
In response to later reporting, CISA said Gottumukkala's use of ChatGPT occurred under an authorized temporary exception and that his last use was in mid-July 2025, disputing accounts that placed uploads in early August.
The ChatGPT uploads generated multiple automated security and data-exfiltration warnings on federal networks designed to prevent sensitive information from leaving government systems.
In summer 2025, Gottumukkala uploaded government contracting documents marked "for official use only" to the public version of ChatGPT. The files were not classified but contained sensitive information not intended for public release.
After arriving at CISA in May 2025, acting director Madhu Gottumukkala was granted a short-term, limited exception to use ChatGPT under DHS controls while the tool was generally blocked for most DHS and CISA personnel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
9 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcego.theregister.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcecsoonline.com
Open sourcearstechnica.com
Open sourcetechcrunch.com
Open sourcetechrepublic.com
Open sourcepolitico.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.