Social Security Administration
Incident posture
Linked entities
- Victim
- Social Security Administration
- Threat actors
- 0 actors
- Sources
- 4 sources
Timeline
Summary
A former employee with the Department of Government Efficiency allegedly stole databases containing Social Security numbers and personal information of more than 500 million Americans by uploading them to an unsecured third-party server and copying them onto a USB drive. The breach, stemming from access granted during work at the Social Security Administration, potentially exposed names, dates of birth, citizenship, and family details of nearly all living Americans. Lawmakers have called the incident potentially the largest data breach in the nation's history.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In 2025, operatives associated with the Department of Government Efficiency (DOGE), a government initiative led by Elon Musk, entered the Social Security Administration (SSA) as part of a broader effort to restructure federal agencies. During this period, DOGE personnel had deep access to SSA systems, with at least one former DOGE employee allegedly claiming to have had "god-level" unlimited access to the agency. The whistleblower testimony, reported by The Washington Post in March 2026, stated that this former employee possessed two highly restricted databases within SSA: "Numident" and "Master Death File." These databases reportedly contained records on more than 500 million Americans, both living and deceased, including Social Security numbers, place of birth, date of birth, citizenship, race and ethnicity, and parents' names. The former DOGE employee left the SSA in October 2025 to work for a government contractor and, upon arriving at the new role, told colleagues that he had obtained copies of the two databases, which he intended to use at a new company. The whistleblower alleged that the former employee planned to store the stolen data on a USB flash drive. The Social Security Administration responded to these allegations by denying that former employees stole personal information from Americans, calling the reporting "fake news" designed to "scare seniors."
Separately, additional whistleblower claims emerged regarding DOGE's handling of SSA data on a much larger scale. According to reporting from August 2025, a whistleblower alleged that DOGE uploaded a live copy of the Social Security database to an unsecured third-party server. This database was reported to contain the Social Security numbers and associated personal information of most living Americans, making it one of the most sensitive repositories of citizen data in the United States. Court filings revealed that the SSA itself was uncertain about what exactly was stored on the server, complicating the scope of the potential exposure. As the situation developed through 2026, investigations and lawsuits continued in federal court, with the full extent and nature of the data exposure remaining unclear. The SSA indicated in court documents that DOGE had signed an agreement with an outside political advocacy group under the pretext of finding evidence of voter fraud—an initiative that President Trump continued to claim was legitimate, despite the absence of supporting evidence.
The potential ramifications of this incident drew significant attention from members of Congress. Two senior House Democrats leading investigations into DOGE's activities at the Social Security Administration stated that the exposure of the government's Social Security database "could very well be the largest data breach in our nation's history." Concerns were raised that the database could be misused to target Americans for spurious reasons, particularly given the involvement of a political advocacy group in the data-sharing arrangement. The case raised serious questions about the safeguards around federal citizen data during the agency restructuring process and the extent to which DOGE's actions compromised the integrity and security of SSA systems. By mid-2026, the lawsuits and federal investigations into the matter were still ongoing, with no definitive public resolution regarding what data was exposed, who had access to it, or what actions had been taken in response.
As of the most recent reporting, the Social Security Administration had not confirmed the full scope of the data exposure, and the specific contents and security status of the third-party server remained in dispute. The whistleblowers' accounts, denied by the SSA, pointed to systemic vulnerabilities created during the federal restructuring, while congressional investigators characterized the incident as historically significant in terms of potential impact on the American public.
Sources
Sources available to members: 4 sources.