07/24/2026 | Press release | Distributed by Public on 07/24/2026 10:24
Trump put Americans' sensitive private data at risk
Washington, DC - U.S. Senators Sheldon Whitehouse (D-RI) and Ron Wyden (D-OR), the Ranking Member of the Senate Finance Committee, sent a letter to Social Security Administration (SSA) Commissioner Frank Bisignano urging the SSA to finally detail the now-defunct Department of Government Efficiency's (DOGE) activities at the Social Security Administration amid public reporting and whistleblower declarations revealing that DOGE personnel received unauthorized access to American's sensitive personal data.
"We write seeking meaningful transparency regarding the handling of various information security risks involving staff from the so-called Department of Government Efficiency at the Social Security Administration and to follow up on inadequate responses to prior Congressional inquiries on these matters," wrote Whitehouse and Wyden. "Over the past fourteen months, we have repeatedly sought basic information about DOGE's activities at SSA. Your responses have either been unresponsive or later disproved by SSA's own admissions."
Whitehouse, Wyden and Senators Kirsten Gillibrand (D-NY) and Bernie Sanders (I-VT) first wrote to Commissioner Bisignano in November 2025 urging the SSA to take all appropriate steps to guarantee that DOGE's actions did not American seniors exposed to identity theft, fraud, or other risks. In a later Department of Justice (DOJ) court filing, the federal government disclosed that DOGE staffers shared sensitive data on a third-party server - without the knowledge of SSA officials - and shared data with an outside political group. The Washington Post reported in March on a whistleblower disclosure claiming a DOGE employee copied a database of highly sensitive SSA data on a personal thumb drive to share with his new private sector employer.
"These admissions and whistleblower statements damage SSA's decades-long history of protecting Americans' sensitive information and discredit your past assurances to protect Americans' data. It is long overdue you provide the American people a straight answer," concluded the senators.
The DOGE infiltration of SSA and other administrative agencies posed substantial risks to Americans' data and wellbeing. New reporting in the Washington Post found that at least two dozen former DOGE staffers remain embedded in the Trump administration, many of whom have been handed key national security or data security positions. Vulnerabilities and bugs left behind in these systems could put Americans at risk of getting scammed, hacked, or even spied on by foreign governments.
Last July, Whitehouse, Wyden, and Senator Elizabeth Warren (D-MA) introduced the Pick Up After Your DOGE Act, legislation requiring a comprehensive audit of federal agency computer systems and networks accessed by DOGE staff. Without a proper and total review of security vulnerabilities, the risk remains that Donald Trump's Big Tech and AI allies are given unfettered access to a massive trove of Americans' data by former DOGE employees to enrich themselves and undermine their competitors.
A PDF of the letter is available here and the text of the letter is below.
July 22, 2026
The Honorable Frank Bisignano
Commissioner
Social Security Administration
6401 Security Blvd.
Baltimore, MD 21235
Dear Commissioner Bisignano:
We write seeking meaningful transparency regarding the handling of various information security risks involving staff from the so-called Department of Government Efficiency (DOGE) at the Social Security Administration (SSA) and to follow up on inadequate responses to prior Congressional inquiries on these matters.
Over the past fourteen months, we have repeatedly sought basic information about DOGE's activities at SSA.[1] Your responses have either been unresponsive or later disproved by SSA's own admissions.
During your confirmation hearing, you committed to Senator Whitehouse to conduct a total review of SSA's databases and security protocols to ensure Americans' data is protected. In November 2025, we wrote seeking an update on your promised audit of SSA's systems for vulnerabilities left behind by DOGE.[2] Rather than providing the findings of an audit, your January 6, 2026 response simply offered the assurance that "SSA's systems and data are secure and managed under strict security protocols, consistent with Federal and industry standards" and asserted that "neither the Numident database nor any of its data has been accessed, leaked, hacked, or shared in any unauthorized manner."[3]
Your assurance lasted all of a few days. In a January 16 court filing - ten days later - the Department of Justice (DOJ) disclosed that DOGE employees at SSA failed to comply with a federal district court order and may have violated multiple federal and agency data privacy and security policies.[4] Specifically, DOGE employees at SSA shared data via Cloudflare - a third-party server that was not approved for Social Security data - without the knowledge of agency officials.[5] Additionally, a DOGE staffer transmitted an encrypted file that DHS believed to contain the names and addresses of approximately 1,000 individuals drawn from SSA systems to DOGE affiliates outside the agency.[6] To date, SSA has yet to determine with certainty what data was shared in either case.
Most disturbingly, DOJ disclosed in the court filing that a member of SSA's DOGE team signed a "Voter Data Agreement," in his capacity as an SSA employee, with a still unnamed political advocacy group that explicitly sought to use SSA data to challenge election results in certain states.[7] SSA rightly recognized the seriousness of this allegation, prompting two referrals to the Office of Special Counsel for possible Hatch Act violations.[8] However, despite repeated requests from Congress, SSA has refused to provide unredacted information related to these complaints, instead providing heavily redacted documents. SSA's lack of transparency on this matter is made all the more concerning as President Trump continues to double down on dangerous election conspiracy theories heading into the November midterms.[9]
In March 2026, The Washington Post reported on a whistleblower complaint regarding a former DOGE software engineer who had unfettered access to two tightly restricted databases of Americans' personal information. According to the complaint, the individual copied at least one of those databases onto a personal thumb drive and planned to upload the data to his new job's databases for its own use.[10] This complaint follows a separate one filed in June 2025 by Charles Borges, SSA's former chief data officer, who alleged that DOGE staff had uploaded a copy of the Numident database to a cloud environment lacking appropriate oversight.[11] We again wrote to you asking for information about your promised forensic audit of DOGE staff's activity at the agency in March 2026, and again, your reply failed to respond to the inquiries made in our letter.[12]
These admissions and whistleblower statements damage SSA's decades-long history of protecting Americans' sensitive information and discredit your past assurances to protect Americans' data. It is long overdue you provide the American people a straight answer. In light of the developments described above, we ask that you provide written responses to our outstanding questions we previously sent to you no later than July 31, 2026:
From our March 24, 2026 Letter:
From our November 21, 2025 Letter:
We respectfully ask that you provide:
We appreciate your attention to these matters and look forward to a substantive response to each of the questions above.
###
[1] Letter from Senator Gillibrand et al. to Acting Commissioner Dudek (April 8, 2025); Letter from Senator Warren et al. to Acting Commissioner Dudek (April 23, 2025); Letter from Senator Gillibrand et al. to Commissioner Bisignano (June 23, 2025); Letter from Senator Whitehouse et al. to Commissioner Bisignano (November 21, 2025).
[2] Letter from Senator Whitehouse et al. to Commissioner Bisignano (November 21, 2025).
[3] Letter from Commissioner Bisignano to Senator Whitehouse et al. (January 6, 2026).
[4] Notice of Corrections to the Record at 5, AFSCME v. Social Security Administration, No. 25-cv-00596-ELH (D. Md. Jan. 16, 2026), https://s3.documentcloud.org/documents/26496273/doge.pdf.
[5] Id at 6.
[6] Id at 3.
[7] Id at 5.
[8] Id.
[9] David E. Sanger and Dustin Volz, "Trump Promised Proof of Election Tampering. His Document Release Fell Far Short," The New York Times (July 17, 2026), https://www.nytimes.com/2026/07/17/us/politics/trump-election-tampering-document-release.html
[10] Meryl Kornfield, Elizabeth Dwoskin, and Lisa Rein, "Whistleblower claims ex-DOGE member says he took Social Security data to new job," The Washington Post (Mar. 10, 2026), https://www.washingtonpost.com/politics/2026/03/10/social-security-data-breach-doge-2/
[11] Nicholas Nehamas, "DOGE Put Critical Social Security Data at Risk, Whistle-Blower Says," The New York Times (August 26, 2025), https://www.nytimes.com/2025/08/26/us/politics/doge-social-security-data.html?eafs_enabled=false
[12] Letter from Senator Wyden et al. to Commissioner Bisignano (March 24, 2026); Letter from Commissioner Bisignano to Senator Wyden et al. (April 16, 2026)