Cited, verified accountability journalism.

Crosscheck

Fact-check

DOGE's Federal Data Dragnet: Access Was Real, Broad, and Poorly Controlled

DOGE accessed at least 12 agencies' sensitive databases over 18 months. Multiple IG investigations confirmed mishandling. One D.C. case is now in discovery.

By · 2026-08-07

True

DOGE staffers were granted access to sensitive federal data systems including SSA, IRS, Treasury payment, and OPM records under the justification of identifying government efficiency savings

True

The access extended to at least 12 federal agencies, far beyond the four named in the claim, including CFPB, HHS/CMS, Education, Labor, USCIS, and Veterans Affairs

Mostly True

Multiple lawsuits and at least one federal Inspector General report have raised concerns about how that access was obtained and how the data was subsequently handled

True

A confirmed specific incident of data mishandling occurred: an unencrypted Excel file containing PII for 350 USAID payment recipients was transmitted outside Treasury without authorization

The Claim

Mostly True

"During its operation (January 2025 through its July 2026 sunset), DOGE staffers were granted access to sensitive federal data systems containing Americans' personal information — including Social Security Administration, IRS, Treasury payment, and Office of Personnel Management records — under the justification of identifying government efficiency savings. Multiple lawsuits and at least one federal Inspector General report have raised concerns about how that access was obtained and how the data was subsequently handled."

Every factual element in this claim is supported by documentary evidence. The "Mostly True" rating reflects two ways the claim undersells what happened: it lists four agencies when access spanned at least twelve, and it describes "at least one" IG report when in fact multiple Inspector General offices opened investigations and the GAO issued a formal report with documented findings. The claim also leaves the harder interpretive question (whether the efficiency mission was a genuine justification or a pretext) as implicit background. That question deserves its own treatment.

The Department of Government Efficiency operated for 530 days, from January 20, 2025, when President Trump signed the founding executive order, through its formal sunset on July 4, 2026. In that period, DOGE staffers were embedded across the federal government with, as one executive order put it, a mandate to receive "full and prompt access to all unclassified agency records, software systems, and IT systems."[2] What followed was the largest peacetime expansion of executive-branch access to federal data systems in modern history, producing at least 12 federal lawsuits, a formal GAO audit, multiple IG investigations, and a Supreme Court ruling that let the administration largely have its way.

Which Systems DOGE Accessed

The claim names four agencies. The actual documented list is substantially longer. Below is what has been confirmed through court records, IG investigations, congressional testimony, and contemporaneous reporting.

Agency / System Data Contents Access Confirmed By
Social Security Administration (SSA) — NUMIDENT, Death Master File, benefit databases Social Security numbers, DOB, citizenship, race/ethnicity, financial records — ~72 million active beneficiaries; 500M+ total historical records Court filings; administration's own admissions; SSA OIG investigation
Treasury / Bureau of the Fiscal Service (BFS) — 3 payment systems Federal income tax refunds, benefit payments, salaries, foreign aid disbursements GAO-26-108131; court records
Office of Personnel Management (OPM) — personnel systems Background checks, medical records, biometric data, salary/benefit records for federal employees AFGE v. OPM (S.D.N.Y.); OPM IG investigation; court orders
Internal Revenue Service (IRS) — taxpayer databases Hundreds of millions of tax returns; bank account routing numbers for all e-refund recipients Center for Taxpayer Rights v. IRS (D.D.C.); court orders; congressional letters
Dept. of Education / Federal Student Aid — Financial Management System, Partner Connect SSNs, DOBs, account information, driver's license numbers for all federal student loan borrowers Warren/Duckworth Senate investigation; court proceedings
USCIS / DHS — DBIS, Databricks, ELIS, Central Index System Green card and naturalization applications; medical and financial data; DACA, TPS, and undocumented immigrant records USCIS CIO memo (March 28, 2025); FedScoop reporting
Consumer Financial Protection Bureau (CFPB) — 40+ systems Consumer financial complaint records, enforcement case data, contract and HR systems NTEU lawsuit; NPR reporting (March 2025)
HHS / Centers for Medicare & Medicaid Services — 19 databases Medicare and Medicaid payment records; national wage/employment database for child support enforcement House Oversight Committee; NPR reporting
Dept. of Labor — OSHA IMIS, EBSA enforcement systems Workplace safety enforcement data; employee benefits enforcement records DOL leadership directives; court filings
Dept. of Veterans Affairs Military service records Harvard Ash Center analysis; congressional oversight
Securities and Exchange Commission (SEC) Personnel communications; financial oversight data SEC internal emails; contemporaneous reporting
Treasury / IRS address-sharing (ICE) Taxpayer address data shared with immigration enforcement D.D.C. court injunction (November 2025)

One DOGE staffer (Akash Bobba) held simultaneous access to SSA data, OPM personnel files, and Education Department systems.[8] Courts noted that this kind of cross-agency simultaneity had no precedent in routine fraud-and-abuse audits.

True

DOGE cited executive order authority, requiring agencies to provide "full and prompt access to all unclassified agency records, software systems, and IT systems."

Executive Order 14158 (January 20, 2025) is the primary authority, and the text does contain that language. A second executive order (February 26, 2025) expanded spending-review powers. This is the stated justification and it is accurately described.

Contested

Whether the executive order lawfully overrides the Privacy Act and agency-specific data protection statutes.

This is a live legal dispute. The administration argued that DOGE staffers, properly installed as agency employees, qualify for the Privacy Act's "need to know" exception, meaning their duties require the records. Courts have split: district courts in Maryland and New York found the access likely violated the Privacy Act; the Fourth Circuit and Supreme Court largely sided with the administration on standing and irreparable-harm grounds, without a clean merits ruling that the access was lawful.

The Privacy Act of 1974 restricts federal agencies from disclosing records from a system of records without written consent, unless an exception applies. DOGE relied on the intra-agency "need to know" exception: employees may access records necessary to perform their duties. Critics argued that DOGE staffers were not bona fide employees in all cases, that the disclosures fell outside published System of Records Notices, and that the executive order cannot override statutory protections enacted by Congress.[1] A Congressional Research Service analysis concluded that courts had not squarely ruled on the statutory question; most injunction battles were resolved on procedural grounds like standing and irreparable harm.

What Federal Courts Actually Ruled

True

Multiple lawsuits challenged the access; courts were divided; the administration generally prevailed at the appellate level.

At least 12 federal lawsuits were filed. District courts in Maryland (twice), New York, and the D.C. Circuit initially granted or partially granted injunctions. The Supreme Court and Fourth Circuit sitting en banc ultimately lifted the most significant injunctions on procedural grounds. One key D.C. case is now in discovery, with the court's blessing, as of August 2026.

The litigation unfolded in distinct stages:

SSA case (AFSCME v. SSA, D. Md., Judge Ellen Hollander): On April 17, 2025, the court granted a preliminary injunction blocking DOGE access to SSA records, finding the access likely violated the Privacy Act and Social Security Act and would cause irreparable harm. The Fourth Circuit initially upheld this injunction, then the full Fourth Circuit reversed course after the Supreme Court stepped in.[5] On June 6, 2025, the Supreme Court stayed the injunction in Social Security Administration v. AFSCME, 24A1063, allowing DOGE access to continue pending full merits review.[6] On April 10, 2026, the en banc Fourth Circuit vacated the preliminary injunction, holding that plaintiffs had not demonstrated sufficient irreparable harm.[7] The case returned to the district court. As of August 2026, district-level proceedings continue.

Treasury/OPM/Education case (AFT v. Bessent, D. Md.): An initial preliminary injunction was vacated by a Fourth Circuit panel (2-1, Judges Richardson and Agee in the majority; Judge King dissenting) in 2025, with the majority citing the Supreme Court's SSA ruling as precedent. The court found that plaintiffs' Privacy Act claims appeared difficult to sustain given the administration's need-to-know arguments. Case remains in litigation.

OPM case (AFGE v. OPM, S.D.N.Y.): A court granted a preliminary injunction blocking OPM database access. Appeals followed. The government argued successfully that at least some injunctions should be vacated pending higher-court resolution.

IRS case (Center for Taxpayer Rights v. IRS, D.D.C.): On April 28, 2025, Judge Tanya Chutkan authorized DOGE adviser Gavin Kliger to access IRS records. In November 2025, the same court blocked IRS from sharing taxpayer address data with DHS/ICE under a separate "address-sharing policy" the court found unlawful.

D.C. Privacy Act case (five federal employees): In March 2026, Judge Alston allowed a Privacy Act lawsuit to advance to discovery, noting that the government itself had admitted DOGE staffers "mishandled agency data in precisely the ways Plaintiffs feared." This case is in active discovery as of August 2026 and may produce the first compelled accounting of what data was accessed and how it was used.[4]

FOIA case (U.S. DOGE Service v. CREW): The Supreme Court, on June 6, 2025, also exempted DOGE from disclosing internal recommendations under FOIA, citing separation-of-powers concerns about judicial inquiry into executive communications. SCOTUS has indicated it may take a full petition on the FOIA question; a petition was pending as of early August 2026.[4]

"DOGE received far broader data access than the SSA customarily affords for fraud, waste, and abuse reviews."
— Justice Ketanji Brown Jackson, dissenting, SSA v. AFSCME (June 2025)

What Inspector General Reports Found

Mostly True

"At least one federal Inspector General report has raised concerns about how that access was obtained and how the data was subsequently handled."

Accurate but conservative. At least three separate IG-level investigations were opened or resulted in findings: a formal GAO audit of Treasury (GAO-26-108131), an SSA OIG investigation into whistleblower allegations, and an OPM OIG inquiry. The GAO report produced specific documented findings of improper handling, not just concerns.

GAO-26-108131 (Treasury / Bureau of the Fiscal Service, April 28, 2026): The Government Accountability Office examined DOGE access to three BFS payment systems between January 20 and April 11, 2025. Key findings:[3]

  • Two DOGE staffers accessed systems handling federal income tax refunds, salaries, benefits, and foreign aid payments. One was granted permissions to "view, copy, and print" data.
  • The same employee was inadvertently given temporary access to create, modify, and delete data in one system. GAO found no evidence of changes.
  • BFS failed to implement 9 of 14 selected cybersecurity controls before granting access (GAO-26-108131).
  • The employee never completed required security training and never signed the required rules-of-behavior document.
  • The employee left BFS with an active interim security clearance that still permitted system access.
  • Treasury could not provide documentation confirming its own Privacy Office had agreed that a confirmed PII transmission was "low risk."
  • GAO issued 6 recommendations; Treasury agreed to implement 3. Treasury said reviewing all external unencrypted transmissions was "infeasible."[3]

SSA Office of Inspector General (March 6, 2026): The SSA OIG notified Congressional leaders that it had opened an investigation into an anonymous whistleblower complaint alleging misuse of SSA data by a former DOGE employee. The investigation remains open as of August 2026.[9]

OPM Office of Inspector General (March 2025): The OPM OIG initiated a review of cybersecurity risks related to DOGE access to OPM IT networks, following congressional requests. Deputy IG Norbert Vint confirmed the review was underway. No final public findings had been released as of known records.[11]

Additionally, in January 2026, the Trump administration admitted in SSA court proceedings that DOGE workers had (a) obtained unauthorized access to sensitive SSA data, (b) shared SSA data using an unapproved third-party service, and (c) engaged in activities outside the scope of SSA's mission. These admissions came from the administration's own legal filings, not from adversarial allegations.[12]

Confirmed Data Mishandling Incidents

True

At least one specific incident of improper data handling was confirmed by an independent watchdog.

GAO confirmed the unencrypted USAID PII transmission. Additional incidents are credibly alleged and under investigation but not yet confirmed by independent findings as of August 2026.

The 350-recipient USAID transmission (confirmed): GAO documented that a DOGE employee at BFS sent an unencrypted Excel file containing the PII of 350 USAID payment recipients to a BFS colleague via Treasury email. That colleague then transmitted the same unencrypted file to two DOGE members at the General Services Administration, outside Treasury, without BFS approval, and without the Privacy Office sign-off that BFS claimed had occurred.[3] The file was not discovered until a forensic review of the employee's laptop after departure. BFS's own data-loss-prevention tools failed to flag or block the transmission.

The John Solly thumb-drive allegation (alleged, under investigation): In March 2026, a whistleblower complaint alleged that John Solly, a former DOGE engineer at SSA, had copied NUMIDENT (the master SSA database containing all Social Security number application records) and the Death Master File to a personal thumb drive. The two databases together contain records for more than 500 million living and deceased Americans, including Social Security numbers, places and dates of birth, citizenship status, race and ethnicity, and parents' names. The whistleblower further alleged that Solly sought assistance transferring data from the thumb drive to a personal computer and "sanitizing" it before uploading to Leidos, an IT firm that holds significant SSA contracts and where Solly subsequently worked. Both Solly and Leidos deny the allegations. The SSA OIG investigation was ongoing as of March 17, 2026.[10] No independent findings or charges had been publicly confirmed as of August 2026. This allegation should not be treated as confirmed.

Unapproved third-party service (admitted): The administration's own January 2026 court filings in the SSA case confirmed that DOGE workers shared SSA data using an unapproved third-party service. No formal IG finding on this incident had been published as of August 2026.

August 2025 whistleblower (SSA, alleged): SSA's then-Chief Data Officer Charles Borges filed a whistleblower complaint alleging that DOGE had copied NUMIDENT to an unaudited private cloud server without independent security controls. Borges resigned three days later. The allegation has not been independently confirmed by an IG finding as of August 2026.[12]

Was the Data Access Tied to Actual Savings?

The efficiency mission's central claim was that data access would identify fraud, waste, and abuse. The record on whether the data access was actually used to find savings is ambiguous.

DOGE did terminate contracts, grants, and leases, and some of those terminations did require knowledge of payment data. The GAO's separate savings audit (GAO-26-108615) confirmed that some contract and lease terminations were real, though it found that 56.7% of listed contract terminations were either not completed or unverifiable, and 96.2% of grant savings lacked verifiable methodology.[15] Verified savings ranged from independent estimates of $1 billion to $10 billion against DOGE's claim of approximately $110 billion.

What the record does not show is a documented link between access to the specific high-sensitivity systems (NUMIDENT, IRS tax returns in bulk, USCIS immigration records, the complete CFPB enforcement database) and the contract or grant terminations DOGE claimed. Identifying a duplicate vendor payment in Treasury's BFS requires access to payment records. It does not require the complete Social Security number history for 500 million Americans, immigration medical records, or the full Internal Revenue database. Justice Jackson's observation that DOGE received "far broader data access than SSA customarily affords for fraud, waste, and abuse reviews" is a precise description of the proportionality problem. DOGE sunset on July 4, 2026, without issuing a final report linking its data access to specific savings findings.[14]

Pretext or Byproduct? The Central Question

The editor's core question is whether DOGE's efficiency framing was a deliberate ruse for data access or a real mission that generated poorly controlled side effects. The public record does not cleanly support either conclusion. The framing itself may be the wrong starting point.

The "deliberate ruse" reading requires evidence that DOGE officials knew from the outset that they were using efficiency as cover to acquire data for other purposes. No document, sworn testimony, or IG finding in the public record establishes that intent. The absence of such evidence is not proof of innocence, but it does mean the ruse conclusion rests on inference from bad optics rather than documented purpose.

The "poorly controlled byproduct" reading, on the other hand, requires believing that DOGE needed all twelve agencies' sensitive records to audit contracts and grants, a claim that strains credulity given that standard fraud-and-waste audits have historically operated with more limited access. The administration's own admissions (unauthorized access, unapproved third-party services, activities "outside the scope of SSA's mission") are hard to square with careful, mission-driven data use.

A third reading fits the evidence better. The efficiency mission was functionally real: DOGE did cut programs and did examine payment data. But the executive order's demand for "full and prompt access to all unclassified agency records" created an organizational environment where data acquisition became an end in itself, whether because individual staffers exceeded their mandate, because the administration treated broad access as a tool for identifying programs to cut on political grounds, or because the centralized-database project documented by the Washington Post and Brookings reflects ambitions that were always larger than contract-line auditing. The record supports this reading without requiring a claim about anyone's original intent.

The Steelman: Why Defenders Say the Access Was Necessary

The Case for Broad Access

DOGE's defenders make several arguments that deserve direct engagement rather than dismissal.

Modern fraud detection requires cross-agency data. Detecting someone who collects both Social Security disability and federal employee salary requires seeing both SSA and OPM records simultaneously. Detecting duplicate vendor payments requires matching BFS payment records against Treasury contracts. The silos that Privacy Act defenders want to preserve are the same silos that allowed fraud to persist for decades. A genuine waste-and-fraud audit, done right, needs cross-system access.

"Read-only" access is categorically different from data theft. For the BFS systems, GAO confirmed that DOGE staffers had "view, copy, and print" access and that no data was modified. The inadvertent "create/modify/delete" access was an administrative error, not deliberate acquisition of write permissions, and GAO found no evidence it was used.

The executive order provided a lawful framework. Courts, including the Supreme Court, have largely declined to hold that the access was unlawful on the merits. Preliminary injunctions were denied or vacated primarily on procedural grounds (standing, irreparable harm). The administration is entitled to rely on a legal structure the courts have not struck down.

Federal IT systems are notoriously fragmented. Understanding how federal money flows requires seeing multiple systems together. Any serious modernization effort would need to audit the full stack. Defenders argue that critics are conflating "access to understand the system" with "access to exploit personal data."

Score on these arguments: The cross-agency fraud detection case is strong for BFS payment systems and for matching SSA against OPM. It is much weaker for full USCIS immigration records, the entirety of the IRS tax database, and the NUMIDENT master file. The "read-only" argument does not address the confirmed unencrypted transmission of the 350-person USAID file, the unapproved third-party service use, or the whistleblower allegations. The legal framework argument is procedurally accurate but does not address the substantive statutory questions that courts have not yet decided on the merits. The IT modernization argument explains why DOGE might need system access; it does not explain why individual staffers needed personal records for 500 million Americans.

Who Gained and Who Lost

Actor Outcome Why
Administration / DOGE Mixed Got access to data and used it to cut programs; faced sustained legal and oversight resistance; sunset without a final accounting; multiple confirmed compliance failures.
Americans whose records were accessed Lost Personal records accessed by political appointees and private contractors with variable vetting, across agencies that historically kept data separate. No notification required or given. Courts provided only intermittent protection.
Federal employees Lost OPM personnel files, medical records, and security clearance data accessed by DOGE staffers outside normal HR oversight. Some short-term injunctive relief; access ultimately continued.
Privacy / civil liberties groups Mixed Won some early injunctions and the right to discovery; lost most appellate battles; one D.C. case may produce a first-ever compelled accounting of what data was actually taken and used.
Congress / oversight bodies Mixed GAO and multiple IGs opened investigations and confirmed problems; no enforcement mechanism followed; administration declined to answer most information requests; executive privilege limited legislative access.
Courts Mixed Showed capacity to constrain at the margins; the Supreme Court's intervention set a precedent that executive efficiency mandates can override agency-level data-sharing restrictions without a full merits ruling.

What to Watch

Forward Look
1
D.C. Privacy Act discovery (ongoing) A D.C. federal court has authorized discovery in the five-employee Privacy Act lawsuit, with the judge citing the government's own admission of data mishandling. What compelled disclosure reveals about what was actually accessed, copied, or transmitted may be the first independent public accounting of DOGE's full data footprint. Watch for any document production orders and government privilege assertions.
2
SSA OIG investigation into John Solly allegations The SSA Inspector General opened a formal investigation in March 2026. If the thumb-drive allegation is confirmed, it would be the most serious documented breach: an instance of potential criminal data theft rather than a control failure. A finding either way will significantly shape the pretext-vs-byproduct debate.
3
Supreme Court FOIA petition (CREW v. DOGE) SCOTUS was weighing whether to take the FOIA case as of early August 2026. A full merits ruling on whether DOGE constitutes an "agency" subject to disclosure requirements could either open DOGE's records to public review or permanently insulate executive efficiency operations from transparency law.
4
Treasury GAO recommendations compliance Treasury agreed to implement only 3 of 6 GAO recommendations from GAO-26-108131. GAO's follow-up on whether those three were actually implemented, and whether Treasury revisits the remaining three, will indicate whether BFS has fixed the controls that let the 350-recipient PII incident happen.
5
Legacy: U.S. DOGE Service and successor operations The formal July 4 sunset applied to the original DOGE entity. The U.S. DOGE Service, its successor body, continues to operate. Whether data-access practices from DOGE's 18-month run were formalized, extended, or expanded into USDS's ongoing work is not yet publicly documented.

Sources

  1. Privacy Act Lawsuits and the Department of Government Efficiency (DOGE)
  2. Ensuring Lawful Governance and Implementing the President's "Department of Government Efficiency" Deregulatory Initiative
  3. DOGE duo ducked security rules during Treasury stint, GAO finds
  4. DOGE Privacy Lawsuit Survives Dismissal: Discovery May Force Data Reckoning
  5. DOGE's Data Dive Denied: Court Grants Preliminary Injunction and Blocks Access to SSA System
  6. SSA v. AFSCME, No. 24A1063
  7. Appeals court removes limits on DOGE access to SSA data despite 'alarming' revelations
  8. Understanding DOGE and Your Data
  9. Social Security watchdog opens probe into alleged misuse of data by ex-DOGE employee
  10. DOGE employee stole Social Security data and put it on a thumb drive, report says
  11. OPM inspector general will examine DOGE access to IT systems
  12. Federal Employee Data Privacy After DOGE: What You Need to Know (2026)
  13. Privacy under siege: DOGE's one big, beautiful database
  14. As DOGE formally sunsets, its public record is still evolving
  15. DOGE Wall of Receipts: More Transparency Needed on How Savings Are Derived from Contract, Grant, and Lease Terminations (GAO-26-108615)
  16. DOGE staffer who shared Treasury data now has more access to government systems
  17. DOGE granted access to naturalization-related IT systems, memo shows
  18. DOGE temporarily blocked from accessing Education Department student aid data
  19. Whistleblower Complaint Alleges Former DOGE Engineer Stole Social Security Data
fact-checkDOGEdata-accessPrivacy-ActSSAIRSTreasuryOPMInspector-Generalfederal-datasurveillanceprivacyDOGE-sunsetgovernment-efficiency

Get the biweekly digest

New Crosscheck fact-checks, every other Monday. Sourced, never spun.