DOGE Running amok in government IT systems

(Nicole Perlroth) I do not care what your politics are. Every American needs to read this entire thread: DOGE went in. Data came out. Russians started logging in *with VALID DOGE passwords* in 15 minutes. Either Russia had access to DOGE devices or someone gave them access. DOGE is not a “government efficiency effort;” it is a national security threat. 

(Matt Johansen) THREAD: A federal whistleblower just dropped one of the most disturbing cybersecurity disclosures I’ve ever read. He’s saying DOGE came in, data went out, and Russians started attempting logins with new valid DOGE passwords. Media’s coverage wasn’t detailed enough so I dug into his testimony:

Who’s the whistleblower? Daniel Berulis — a senior DevSecOps architect at the National Labor Relations Board (NLRB), formerly with TS/SCI clearance. He just told Congress the Department of Government Efficiency (DOGE) pulled off a covert cyber op inside a federal agency.

DOGE demanded root access. Not auditor access. Not admin. They were given “tenant owner” privileges in Azure — full control over the NLRB’s cloud, above the CIO himself. This is never supposed to happen. They disabled the logs. Berulis says DOGE demanded account creation with no recordkeeping. They even ordered security controls bypassed and disabled tools like network watcher so their actions wouldn’t be logged.

And then the data started flowing out. 10+ GB spike in outbound traffic. Exfiltration from NxGen, the NLRB’s legal case database. No corresponding inbound traffic. Unusual ephemeral containers and expired storage tokens. They used an external library that used AWS IP pools to rotate IPs for scraping and brute force attacks. They downloaded external GitHub tools like requests-ip-rotator and browserless — neither of which the agency uses.

The most damning claim in this statement IMO: Within 15 minutes of DOGE accounts being created… Attackers in Russia tried logging in using those new creds. Correct usernames and passwords. 2 options here. The DOGE device was hacked. And I don’t think I need to explain the 2nd.

Multi-factor authentication? Disabled. Someone downgraded Azure conditional access rules — MFA [multi-factor authentication] was off for mobile. This was not approved and not logged.

Cost spikes without new resources. Azure billing jumped 8% — likely from short-lived high-cost compute used for data extraction, then deleted.

Then came the intimidation. While preparing this disclosure, Berulis found a drone surveillance photo of himself taped to his front door with a threatening note. This was just a few days ago.

US-CERT was about to be called in, CISA’s cyber response team. But senior officials told them to stand down — no report, no investigation.

https://x.com/mattjay/status/1913023007263543565

Comment: This is from a thread on X highlighting some of the points from the Congressional testimony of a whistleblower from the NLRB. NPR did an excellent, in depth write up for those interested in the details of this story.

https://www.npr.org/2025/04/15/nx-s1-5355896/doge-nlrb-elon-musk-spacex-security

This story shows that the DOGE boys know how to maneuver in large IT systems. At the very least, it also shows they have a cavalier attitude about the security of the data in those large IT systems. But given the lengths they go to in order to hide their activities on those systems, I think they know exactly what they’re doing. The data is being taken deliberately and in great secrecy. I can’t see how that can further the aims of uncovering fraud, waste and abuse or creating efficiency. Whether they are deliberately aiding the foreign theft of that data or are just indifferent to that theft is a question that Congress is left to answer. Our organizations devoted to cyber defense are being deliberately decapitated and hobbled by the Trump administration. I’m not sure it is being done out of vengeance or for more nefarious reasons.

“Help me, Obi-Wan Kenobi; you’re my only hope.”

TTG

This entry was posted in government, Intelligence, Technology, TTG. Bookmark the permalink.

48 Responses to DOGE Running amok in government IT systems

  1. Eric Newhill says:

    The story is another stinking heap of BS brought to us by the same borg that gave us the Steele Dossier/Russiagate and a dozen other deep state vicious hoaxes. Give it rest already. You lost. Current polls – as in this week – show the majority hate you and everything you do and approve of Trump, DOGE, deportations, etc.

    • TTG says:

      Eric Newhill,

      Current polls show the majority of Americans think this country is going to Hell in a handbasket. The majority disapprove of Trump, but even a larger majority disapprove of all other government institutions and leaders, Democrat, Republican or DOGE. Only Trump’s immigration/deportation policies still enjoy a strong majority approval. If he stuck to deporting obviously dangerous people, it would be even higher. Trump says there are millions of these bad guys out there. Why waste time and money deporting gay hairdressers and questionably gang members until the real bad hombres are gone?

      • Al says:

        TTG, Noted a 1AM Saturday order by SCOTUS stopping Trump admin from flying out a group of migrants held in Texas. Only Thomas and Alito objecting to order.

        ONE AM! How often has that hapoened?

        • TTG says:

          Al,

          The order was to stop using the Alien Enemies Act as a pretext for these deportations. The Trump administration is acting that there’s no other way to deport them. Biden did well over a million deportations without that Act. He deported about as many as Trump did in his first term, which was also done without invoking the Alien Enemies Act. This is a fight Trump is engaging in for the sake of fighting.

          • Al says:

            My sense is that the SCOTUS majority is getting pissed off at Trump’s gang of basic law violators and attacks on the judiciary

          • Lesly says:

            TTG,

            IMO it’s unfair to compare Biden to Trump. We know Biden wasn’t serious about creating the impression that they were unwanted. He had a lot of pickings by the time Harris gave a (paraphrasing) “there is no illegal person” campaign rally speech.

            Obama still has the most deportations at 3m, a fact Democrats would rather forget. Clinton comes second at ~1.5m. If you count deportations and re-entries I think Clinton holds the record at over 10m.

            This 6yo C-SPAN video of Bennet (D-CO) calls out GOP BS on border security about halfway through. Trump made the border issue about himself from the getgo. Grats, I guess.

            https://youtu.be/1LlCn-HZDuY?si=GwFbXUPvr9JTIvQL

          • Laura Wilson says:

            I think the Supreme Court (or at least John Roberts) is starting to fully realize that their OWN CONSTITUTIONAL POWER is at stake. At least they are waking up—the GOP Congress still has come to grips with this fact.

        • TonyL says:

          Al,

          IMO, the emergency order from SCOTUS means they do not trust Trump’s administration promise not to deport these imigrants from Texas over the weekend.

          Probably they took into account the fact that the government evaded the restraining order by a federal judge in the Southern District of Texas, by busing the
          imigrants into the Northern District of Texas.

      • Eric Newhill says:

        TTG,
        I don’t know what polls you look at, but they aren’t the mainstream. Then again, “hell in a handbasket” is a double edged sword. I myself think the country is headed there; not because of Trump, but because of all of the socialists, muslim activists, corrupt progressives, corrupt open border Soros judges, cartel stooge democrat politicians, etc. who have degenerated our culture and are trying to thwart Trump.

        The deported guy you’re all crying about has MS13 tattooed on his knuckles.

        The fact that your side needs to manufacture and disseminate more Russia collusion BS demonstrates desperation to shift public opinion.

        • TTG says:

          Eric Newhill,

          You assume Russian collusion is at the heart of this story. It’s not. It’s peripheral at best. The story is about DOGE secrecy and sloppiness. The Russian hack was most likely an opportunity enabled by DOGE sloppiness. According to a recent “Wired” story, DOGE is constructing the mother of all Big Brother surveillance programs to spy on and investigate all, but especially those designated as Trump’s enemies, with zero oversight. And they’re doing it with total disregard for the security of that data.

          • jim ticehurst.. says:

            TTG….Sir…Elon “DOGE” Musk…{ Odor ?}
            Also Wound Up Creating His Own Position
            With POWER..And Conjured Up (Voodo)
            DOGE.. A Strange Four Letter Name That has
            Some Meaning To Copy Cat….MAGA..
            and BE the Opposite..
            Kennedy Bought In..Musk Bot In.ZUKE Did
            But The Rest of The High Stakes Table….
            Keeps HIDDEN….
            JIM

          • Eric Newhill says:

            TTG,
            This is a stupid lame attack on a group that is looking for federal government waste/fraud/abuse by the leaches that enrich themselves via federal government waste/fraud/abuse.

            Care to discuss how many cyber penetrations of federal government occurred under the Biden admin? Even the US Treasury was hacked. Not a peep out of you lefties. Now you come along with what is a likely a fake story about hacking and it’s all the Trump admin’s fault.

            DOGE constructing a Big Brother surveillance system? Oh please. As you must know very well that has been going on for some time. You probably even helped build some of it. Does the name “Clapper” ring any bells? Obama’s IRS?

            Your TDS is really clouding your thinking. It’s sad on the one hand and funny on the other. Your head is really going to explode when you see what is coming down the pipe with regards to restoring election integrity, which is the key to saving the republic. Therefore, I expect your side to reach new fanatical levels of “resistance” to stop the restoration project.

          • TTG says:

            Eric Newhill,

            Former government surveillance systems don’t come close to what DOGE and Musk are constructing. And at least those government surveillance systems ended up under oversight and regulation. Those systems also stovepiped the data collected. That’s part of the oversight and regulation.The DOGE system is purposefully pulling all that stovepiped data into one huge pile so they can work their AI magic on it totally without oversight and regulation.

          • Eric Newhill says:

            TTG,
            Oversight and regulation? Yeah, by who? Someone(s) more trustworthy just because they’re not Trump/Musk. Okie dookie.

            Facebook, Tik Tok, etc are collecting and analyzing more data and doing more foreign government surveillance than anyone should be comfortable with – and people give that info up voluntarily.

            What are Musk and Trump constructing exactly?

          • TTG says:

            Eric Newhill,

            Oversight and regulation by who? How about Congressional oversight, strong whistleblower protections, robust inspectors general offices.

            You’re right about Facebook and others. Marketing and money is one hell of an incentive to gather all manner of consumer info on all of us. The OPM break in was probably the most damaging theft of US info, the security files of most USG employees. My info wasn’t in there thanks to my SMU past. I’m pretty sure CIA manages their own security files, as well.

            DOGE has already collected mass amounts of personal data harvested from the IRS, SSA, and voting records in Pennsylvania and Florida and uploaded the data into servers at USCIS. And, as you say, they’re just ramping up.

        • Lesly says:

          Eric Newhall:

          “The deported guy you’re all crying about has MS13 tattooed on his knuckles.”

          Hey I saw that. Pretty cool how the tattooed M S 1 3 looks exactlylike the font label above the picture. A real typewriting artist.

          • Eric Newhill says:

            Lesly,
            Yes, curl up into instant conspiracy theory mode when your memes are at risk of being deflated.

          • Eric Newhill says:

            Lesly,
            Look, it’s not just Trump saying Garcia is MS13. A Sheriff’s Dept said it. Two different judges said it. El Salvador is saying it. The only ones doubting his MS13 membership are those afflicted with TDS because a symptom of the affliction is reflexively saying, doing and believing 180% of the Trump admin.

            Trump owns you people. He’s firmly implanted in your head and making you jump through hoops, sit and bark, whatever he wants. All he has to say is, “Don’t jump through that hoop”. “Don’t sit and bark”.

          • Eric Newhill says:

            yeah – he’s got ink all over his body that is MS13.

            https://www.youtube.com/watch?v=sez7Yijgg1A

            describes pretty well.

          • Fred says:

            2 courts confirmed membership and the latest appeal mentions fear of violence from Bario 18, because he was in ms13

  2. babelthuap says:

    AI tools are going to replace much of the Federal government in a few years. The first order of business though is to trim as much fat right now that way it will be less painful.

    The bigger issue however is the bloat of military bases worldwide that serve no purpose for American citizens. Do that and we start running a surplus to invest into American communities. A large prison camp in the middle of Alaska for drug addicts would be a great investment. Round them all up and stick them in our version of Siberia making coffins and other depressing goods.

  3. aleksandar says:

    Bravo Sierra.
    Let DOGE in.
    Wait DOGE out.
    Then sabotage system.
    Add something Russian.
    Suggest that Russians where waiting to access.
    ( everyone knows that National Labor Relations Board data is of great interest to the Russians !)
    Pay a whistleblower or simply persuade him he’s “saving” USA.

    I was wondering when CIA/FBI/DEMs will be back with their stupid propaganda
    ” Trump is a Russian agent “.
    Here we are.

    • ked says:

      Nasty is NOT a Russian agent.
      He is Vlad’s Useful Idiot.
      get it straight, man

    • English Outsider says:

      aleksander – the key to the whole is American military impotence in this theatre.

      That sounds like an Englishman jeering but I assure you it’s not. The Americans are not in the same boat as the Europeans, who don’t really have much in the way of useful armed forces at all. The Americans do have formidable armed forces but those armed forces are simply not designed for an old fashioned slugging match in the middle of Europe. Worse, an old fashioned slugging match with severe constraints on the use of air and naval forces and missiles. Constraints, incidentally, that their opponents are not subject to to anything like the same extent.

      It wasn’t ever supposed to be like this. The Europeans and the Americans expected a quick kill of the Russian economy and financial system. That would have destabilised the RF and with any luck would have got rid of the current Russian administration. The military front was always secondary. Far from a quick kill of the Russian army being expected, we expected the Russians to win a quick military victory and then get bogged down in a long drawn out guerilla war.

      The Americans understood fairly quickly that none of that was going to work and settled down to doing what damage to the Russians they could. “We’re killing Russians for cents on the dollar and no American lives lost doing it” was the message from then on from the States, that and the still current belief that the Russian economy was a Potemkin village that could easily be set back or crippled even if it was not possible to destroy it. In that respect the Americans were blinded by their own exceptionalism throughout the Biden period.

      Then, to the horror of both the American and the European elites, along comes Trump.

      Trump’s a controversial figure and is usually either demonised or idealised. In the turmoil most forget that he’s comes from a ruthless business culture in which doubling down on failure is fatal. Sending good money after bad, failing to cut one’s losses, is alien to that culture. The Ukrainian Venture has turned into a pointless money pit and Trump wants out fast. But he’s having the devil’s own job cutting his losses there. He is trapped by electoral considerations.

      Trump knows by now that the US has neither the weapons nor the men to stop the Russians in Ukraine. But how can he confess that to the American people? They still believe they have the most powerful military in the world. Anyone who tells them the truth, that their military is now very much a boutique military, technologically backward and unsuitable for slugging match wars, is going to get slaughtered in the midterms.

      The Europeans aren’t going to help him. Nor the Banderites. Both are going to play the Dolchstoßlegende for all its worth. This was never a winnable war but “We could have won if the Americans hadn’t let us down” is how both the Europeans and the Banderites are shifting the blame for losing the war onto Trump. And even an outside observer can see than the American Democrats and RINO’s are taking up the same cry.

      And for the more credulous that old smear, that Trump’s a Russian patsy, will lose him yet more votes. Fact is, whatever we in the West do, and no matter the incessant flood of purposeless talk in Europe and the States, the Russians will stolidly plod on until they have achieved their objectives. And Trump will remain trapped. In retrospect he’d have done better to do what Bannon wanted. Said straight after inauguration that this was Biden’s war and he wanted no part of it.

      Too late now. If he doesn’t find some way out of the trap he’s in he’ll find himself being pushed willy-nilly into becoming Biden’s heir. Meanwhile, in that hopeless war thousands of miles away, seems the chest-beating chicken hawks of the West will insist on continuing their valiant fight to the last Ukrainian. Easy to be valiant when you have no skin in the game and it’s only the proxies dying.

  4. Lars says:

    AI training requires a lot of data and Elon is behind and who has vast data bases? The Federal Government does. I predict this will get worse and that it will become a serious problem, even more than it is today.

    I also think that other people, other than me, will demand a lot more accounting in the future as we recover from the destruction spreading today. The last rouge president was Nixon and a bunch of his enablers went to prison. It will likely be worse this time around.

    • babelthuap says:

      What Obama did was change the rule on what was considered a deportation which was not actually physically deporting people. This fact is well known for anyone who wants to marginally look into the matter. Anyone saying Obama had more deportations will never look into it. Also, the housing bust, many illegal started leaving on their own since there was no welfare or jobs. At one point, we had a net loss of illegal aliens.

      As for Biden, there is ample amount of evidence he was letting illegals enter without much of a speed bump. Anyone who believes he was deporting people in mass is either feeble minded, a liar or both.

    • Fredrick says:

      Lars,

      Pirate libraries who bootleg millions of terabytes of data from copyrighted materials they pay nothing for. Google and Meta have both been caught downloading the already pirated materials for use in AI. Nice try on the “elon is doing it” deflection.

  5. leith says:

    The African immigrant running DOGE has major arguments with the NLRB. He fired eight SpaceX engineers after they spoke out about working conditions and criticized Elon’s leadership. After they were fired they filed unfair labor practice charges with the NLRB. Which is exactly why he sicced his attack doggies to steal and/or erase the data there.

    As for the Russkii hackers, they probably got into many other of our Nation’s database, even critical ones. Is it’s Muskrat’s way of trying to deflect the blame or is he or his crue in bed with Putin?.

  6. Lesly says:

    The DOGEis were sourced from Thiel’s Palantir. Plantinr is contracting to to track immigrants, digitally and nationally. I think they’re working on an Iron Dome as well. They received initial funding from a CIA venture company. Thief supported Vance. He thinks democracy is overrated.

  7. Keith Harbaugh says:

    Regarding Palantir, this lengthy article is in large part a critical look at its Zionist co-founder, Alex Karp:

    “Profiling Palantir
    The tech firm beloved by the WEF and founded by Peter Thiel and Zionist zealot, Alex Karp —
    that is watching every last move you make”

    https://www.unz.com/article/profiling-palantir-the-tech-firm-beloved-by-the-wef-and-founded-by-peter-thiel-and-zionist-zealot-alex-karp-that-is-watching-every-last-move-you-make/

    The author of the article makes many claims without backing them up, which is certainly a problem.
    But some of it is actual quotes,
    and the article includes, for whatever they are worth, two photos captioned respectively

    “Good Friends Alex Karp and Volodymyr Zelenskyy”
    and
    “Alex Karp (right), Israeli president Isaac Herzog (middle), Peter Thiel (left) at a meeting in Tel Aviv”.

    The author makes his opposition to Zionism quite clear.

    Questions of loyalties do arise.
    Remember Jonathan Pollard
    https://images.app.goo.gl/6KYLPx8aSgSaFYRm9 .
    How will Palantir be used, and whose interests will be served?

  8. jim ticehurst.. says:

    TTG,,,I Think That Story..About..The Musky Disclosure…Is One of THE Most
    Interesting…For The Moment You Could Have Found. And As Usual..On This
    Thread..I See Who The First and Second Was To Comment…Eric Must
    have Alarms to Your Site TTG..How Can He Publish so Much..so Fast..in a Row…
    Must Be a PRO..
    Jim

  9. Fredrick says:

    ” Someone downgraded Azure conditional access rules — MFA [multi-factor authentication] was off for mobile.”

    Who, when? Not asked.

    I suggest asking disbarred DOJ lawyer Clinesmith. Not that he would know, but it might remind everyone that not all employees of the US government have integrity. Perhaps we could ask Vindman and the “whistleblower” that Chief Justice Roberts would not allow to be named by the Senate either. Just to remind, again, Never Trump exists, and integrity and CNN does not.

    “NLRB’s cloud”

    Why does NLRB need a ‘cloud’? Just how many servers, owned by whom, located where, and manage by what entity? Anybody bother to ask? Just how much work does
    the 1,232 (November 2023) employees of NLRB have going on? How much requires a TS/SCI clearance oh wait that just “bait” to chum the waters and give “credibility”. How much work do 1,200 employees have needing any kind of cloud anywhere?

  10. Al says:

    Hegseth on way out. White House looking for new Sec DOD as several long time Trump supporters fired or resigning from DOD and reporting chaotic mess in DOD

    • Fred says:

      Al,

      Guys and gals S**tcanned by SecDef claim Secdef is on way out. According to “anonymous sources say”. More fake news at 11. Meanwhile the Pope, gravely ill but dragged out by the Curia to read speech prepared by the Curia, dies. The usual suspects blame VP of the US. More fake news at 11.

      US Senator frees wife-beating gang member from El Salvador “death camp”, but not for margaritas, just a photo op. Proving citizen of El Salvador no longer at risk from Barrio 18 gang. No word on how his mother’s pupusa business is going. No more news at 11 as ratings of the party continue to decline.

      • Al says:

        Fred, you sure quickly switch to a different subject when not appreciating the topic! lol

        These former 4 key DOD staff that were hand picked by Whiskey Hag are on the way to spill more about the chaos happening in DOD.

        Soon you will realize Whiskey Hag has been on a “dry drunk” [look that up if not familiar] since his appointment.

        • Fred says:

          Al,

          The subject is service to the republic and the civilian leadership thereof. They were fired for their conduct. Let me know what the guy with the steel toed boot drinks, I’ll send him a barrel.

    • ked says:

      doesn’t matter. all our strategic adversaries likes having him as SecDef.

    • leith says:

      Al –

      Had to believe that Trump would dump SecDef Pete Kegsbreath so soon.

      • Fred says:

        Leith,

        Yeah he’s not going to get conned by a ginned up story like Russia Collusion and fire anyone this time. Only surprised Flynn didn’t come back. That would send a message

    • TonyL says:

      Hegseth shared details of Yemen battle plan in a 2nd Signal group chat that included his wife, his brother, and his lawyer. That was on the same day as the 1st Signal group chat which inadvertently included Jeffrey Goldberg.

      There is hope the SEC will investigate those people for insider trading. Perhaps Trump is mad because only he is allowed to do that. LOL.

      • Fred says:

        TonyL,

        “details of Yemen battle plan”

        According to whom? What and when was that? “details”? What details. Aircraft type, bomb load, launch time, path of travel, transponder codes, pilot names, specific target geographic location and time of attack?

        Too hard?

        SEC insider trading? I agree. I sure hope they look into Nancy Pelosi’s involvement in bailing out Signature Bank in Silicon valley due to the involvement and potential collapse of her husband’s investment firm. Ro Khanna, whose district this bank was in, didn’t make a call to the FED for a bailout, which is really telling. Lots of other details in the podcast here:
        https://tomluongo.me/2025/04/19/podcast-episode-213-caitlin-long-and-the-financial-crisis-that-wasnt/

        • TTG says:

          Fred,

          It was pretty much the same details of the upcoming F/A-18 strikes on Yemen that he shared on the Signal chat with the editor of The Atlantic, except this second Signal chat was set up by Hegseth himself. This separate chat included around a dozen people and was set up on Hegseth’s personal phone. Both chats were concurrent. There were four sources for this second chat group including at least two of the people fired from the Pentagon and Kasper, a Hegseth top aid who has moved on to a different Pentagon job (not fired). Those three were in on the chat.

        • TonyL says:

          Fred,

          I hope TTG has answered your questions.

          And yes, I would like to see the SEC doing more to investigate all probable insider tradings, by Republicans, Democrats, or Independents. But we are talking about Trump’s administration is seemingly leaking classified info for profit here.

  11. Al says:

    Four key top staff leave DOD. Three are fire who were alleged to have leaked (2 of them “close” personal acquaintances to Heg).

    The 4th leaving by resignation was John Ullyot a longtime Trump supporter who recommended Heg get the DOD Sec spot.

    These are not “disgrunted” holdover
    staff , buried in some sort of “Deep State”. But, believers in Trumpism.

    Ullyot was so concerned about the mess under Heg’s “leadership” that he posted an op-ed warning that more “bombshell” leaks will be coming out

  12. Al says:

    Interesting source history on allegations made vs Hegseth…largely conservative or Republican connected:
    1) largely conservatve/patriotic non-profit veterans groups alleging his mismanagement
    2) A conservative Republican woman alleging rape
    3) Fox News colleagues alleging uncontrolled alcohol consumption
    4) Now 4 ex DOD staffers with longtime Republican/Trump connections are openly talking about the chaos in Heg’s DOD.

    This is NOT “news made up by the ‘liberal’ media” but reporting of what those considered to be in the conservative world have been saying.

Comments are closed.