News: 1757613673

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Senator demands to know status of 'duplicate' Social Security database 'immediately'

(2025/09/11)


A US Senator is demanding answers after a Social Security Administration (SSA) employee who blew the whistle on Department of Government Efficiency (DOGE) dealings involuntarily resigned last month, citing workplace hostility in response to his concerns.

Republican Senator Mike Crapo (it's pronounced Cray-poe), chairman of the Senate Finance Committee, sent a [1]letter to the SSA's commissioner, Frank Bisignano, giving him just two weeks to provide answers to [2]concerns raised last month by now-former SSA Chief Data Officer Charles Borges. The former CDO's whistleblower complaint alleged DOGE had duplicated a critical database filled with taxpayer information, known as Numident, to a test cloud environment that wasn't managed by Borges or SSA, and which allegedly is without any oversight controls.

As Chairman of the Senate Committee on Finance, I must take very seriously every allegation made by a protected whistleblower ... I consider the protection and security of PII held by the agency to be a matter of first importance

Numident is used to store records of every person who has ever applied for a Social Security Card in the United States.

Crapo's questions are numerous, but one with a much shorter deadline stands out: He wants to know whether that duplicate database "was accessed, leaked, hacked, or disseminated in any unauthorized fashion," and he wants it "immediately upon receipt of this letter."

"As Chairman of the Senate Committee on Finance, I must take very seriously every allegation made by a protected whistleblower," Crapo added. "Further, given the large amount of sensitive data under SSA's control, I consider the protection and security of PII held by the agency to be a matter of first importance."

[3]

The SSA didn't directly answer questions about its response to Crapo, instead sending us an identical statement to the one it provided when we covered the original whistleblower complaint last month.

[4]

[5]

"We are not aware of any compromise to this environment and remain dedicated to protecting sensitive personal data," an SSA spokesperson said, while maintaining that Numident data is stored "in secure environments that have robust safeguards in place to protect vital information." That doesn't explain the security of the alleged unauthorized copy of Numident. We pointed this out to the SSA, but haven't heard back.

Borges' complaint was primarily about the Numident copy, but he also raised concerns over his beliefs that DOGE had allegedly committed numerous "systemic data security violations" as well as violations of SSA protocols and federal data privacy laws in its time at the SSA.

[6]Dems fret over DOGE feeding sensitive data into random AI

[7]Whistleblower describes DOGE IT dept rampage at America's labor watchdog

[8]Dems look to close the barn door after top DOGE dog has bolted

[9]Judge cites big OPM records leaks from 2015 in DOGE slapdown

In response to his concerns, Borges said in his [10]resignation letter late last month that SSA's actions created a hostile work environment that made it impossible for him to fulfill his duties ethically or lawfully, caused significant distress, and effectively forced him from his role as chief data officer.

"After reporting internally to management and externally to regulators serious data security and integrity concerns impacting our citizens' most sensitive personal data, I have suffered exclusion, isolation, internal strife, and a culture of fear, creating a hostile work environment and making work conditions intolerable," Borges wrote in his letter to Bisignano. "SSA's actions against me [have made] my duties impossible to perform legally and ethically."

[11]

In addition to his demand for answers about the integrity of the alleged Numident duplicate, Crapo is also demanding to know how SSA dealt with Borges' internal complaints, details about its use of cloud storage and data security mechanisms, and asks about how it assessed the risk of giving agency employees the ability "to transfer data from the Numident database to a private cloud within SSA's AWS cloud environment."

Neither Crapo's office nor the Senate Finance Committee responded to questions for this story. ®

Get our [12]Tech Resources



[1] https://www.finance.senate.gov/chairmans-news/crapo-requests-information-on-social-security-data-protections

[2] https://www.theregister.com/2025/08/26/whistleblower_accuses_doge_of_duplicating/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aMNGc13CrlDqmPv6iWbniwAAABY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aMNGc13CrlDqmPv6iWbniwAAABY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aMNGc13CrlDqmPv6iWbniwAAABY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2025/04/18/house_democrats_doge/

[7] https://www.theregister.com/2025/04/17/whistleblower_nlrb_doge/

[8] https://www.theregister.com/2025/05/01/dems_ask_for_musks_financial/

[9] https://www.theregister.com/2025/06/10/judge_doge_opm_records/

[10] https://whistleblower.org/press/social-security-whistleblower-resigns-after-revealing-millions-of-americans-data-was-put-at-risk/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aMNGc13CrlDqmPv6iWbniwAAABY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



Eclectic Man

The former CDO's whistleblower complaint alleged DOGE had duplicated a critical database filled with taxpayer information, known as Numident, to a test cloud environment that wasn't managed by Borges or SSA, and which allegedly is without any oversight controls.

If the database he is concerned about is in the possession of DOGE, then surely the Senator should be asking them, not the SSA?

At least he is doing something.

Tron

Most Republicans have entirely abrogated their duties.

He seems to be doing what he can within the remit of his position. Going after DOGE would just be inviting Trump to have a go at him and a bunch of MAGA loons to target him.

After all, the 'protected whistleblower' doesn't seem to have had much protection.

Re: At least he is doing something.

Anonymous Coward

"Most Republicans have entirely abrogated their duties"

Short term political expediency and self interest has a cost though, and its a shame that the Republican party are so insular that they have not learned any lessons from overseas. Here in the UK, we used to have a government composed of a party called the Conservatives. After a good few years of their elected representatives practising expediency and self interest, voters cast them into the pit of fire, and there's been no signs of voters letting them crawl out so far. I'd see myself as somebody who by background, beliefs and personal circumstance ought to be a centre-right core voter. But after the shit show of the last Conservative government I vowed I'd never vote for the party again - and I mean it. No matter what alternatives are standing, there is no way those f***ers will ever get my vote.

And that, my American friends, is the ghost of Christmas future for the Republican party.

And ever has it been known that love knows not its own depth until the
hour of separation.
-- Kahlil Gibran