A whistleblower complaint alleges a former employee associated with Elon Musk’s Department of Government Efficiency (DOGE) improperly accessed and removed highly sensitive U.S. Social Security Administration (SSA) data, storing it on a thumb drive and later claiming he brought the data to a new job. Reporting indicates the individual told colleagues at a government contractor that he possessed two tightly restricted SSA datasets—Numident and the Master Death File—and planned to use or share the information at his new employer; the datasets reportedly contain large-scale personally identifiable information (PII) such as Social Security numbers and birth details.
The SSA’s Office of Inspector General is investigating the allegations and has reportedly notified members of Congress, according to correspondence reviewed by The Washington Post and sources familiar with the matter. The reporting frames the alleged conduct as a potentially unprecedented breach of SSA security protocols and notes it follows earlier concerns and legal claims about DOGE-linked access to restricted Social Security data and handling of large volumes of SSA records.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Sen. Gary Peters urged an independent investigation into reports that DOGE representatives may have improperly accessed and transferred sensitive SSA data. He also sent letters to SSA officials seeking records, communications, interviews, and risk assessments related to DOGE's work at the agency.
In response to reporting on the allegations, an SSA spokesperson said no SSA data breach had occurred and described the reports as "fake news." This marked the agency's public denial of the alleged incident.
The Social Security Administration Office of Inspector General began investigating allegations that a former DOGE employee improperly retained access to highly sensitive SSA databases and planned to share the data with a private employer. The acting inspector general also notified senior members of four congressional committees by letter.
A judge previously barred DOGE from accessing Social Security Administration systems, criticizing the effort as a "fishing expedition" for fraud. The ruling is cited as part of broader concerns over DOGE's access to SSA data.
After moving to a government contractor job in October, the former DOGE employee allegedly told coworkers he possessed the SSA datasets and intended to use or share the information at his new company. The allegation was included in a whistleblower complaint.
A whistleblower complaint alleges that a DOGE software engineer removed data from two tightly restricted Social Security Administration databases, Numident and the Master Death File, and stored it on a USB/thumb drive. The data reportedly could include sensitive records on more than 500 million living and deceased Americans.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.