US Cyber Defense Chief Uploaded Sensitive Files Into a Public Version of ChatGPT (politico.com)
- Reference: 0180680554
- News link: https://yro.slashdot.org/story/26/01/28/2144213/us-cyber-defense-chief-uploaded-sensitive-files-into-a-public-version-of-chatgpt
- Source link: https://www.politico.com/news/2026/01/27/cisa-madhu-gottumukkala-chatgpt-00749361
> The interim head of the country's cyber defense agency [1]uploaded sensitive contracting documents into a public version of ChatGPT last summer , triggering multiple automated security warnings that are meant to stop the theft or unintentional disclosure of government material from federal networks, according to four Department of Homeland Security officials with knowledge of the incident. The apparent misstep from Madhu Gottumukkala was especially noteworthy because the acting director of the Cybersecurity and Infrastructure Security Agency had requested special permission from CISA's Office of the Chief Information Officer to use the popular AI tool soon after arriving at the agency this May, three of the officials said. The app was blocked for other DHS employees at the time.
>
> None of the files Gottumukkala plugged into ChatGPT were classified, according to the four officials, each of whom was granted anonymity for fear of retribution. But the material included [2]CISA contracting documents (PDF) marked "for official use only," a government designation for information that is considered sensitive and not for public release. Cybersecurity sensors at CISA flagged the uploads this past August, said the four officials. One official specified there were multiple such warnings in the first week of August alone. Senior officials at DHS subsequently led an internal review to assess if there had been any harm to government security from the exposures, according to two of the four officials. It is not clear what the review concluded.
[1] https://www.politico.com/news/2026/01/27/cisa-madhu-gottumukkala-chatgpt-00749361
[2] https://www.dhs.gov/sites/default/files/publications/Management%20Directive%2011042.1%20Safeguarding%20Sensitive%20But%20Unclassified%20(For%20Official%20Use%20Only)%20Information_0.pdf
More violations than at a high school or unversity (Score:3)
ChatGPT has a version which is FERPA compliant, and high school and university teachers are told explicitly not put any student names or anything else sensitive into personal ChatGPT or other AI accounts. I don't use the teacher version of ChatGPT, in part because I've never had need of any interaction with an AI where having an AI would be useful and where a student's name or other identifying info would show up. I honestly struggle at seeing what the reasonable use cases are in that intersection. (Also, I'm slightly cynical/skeptical about their promises to not use anything from those accounts for new training data.) But the bottom line is that this sort of thing is something which would get stern rebukes up to being fired if it happened in a high school environment. And this is the nominal head of cyber security for the US government. So the question is how much of this is part of the Trump's administrations general tendency to not hire people who are competent, how much is the tendency for people (in any administration) who are powerful to just ignore the rules, and how much of this is that there are some people who are really into credulously using LLM AIs and are just idiots?
Of course (Score:3)
Because despite the fact that this man holds a Bachelors in engineering, Masters in Comp Sci, a useless MBA, and a PhD in information systems... he's a fucking retard and has no clue what the fuck he is doing. He probably never actually earned those degrees legitimately. He certainly hasn't done any work that proves his knowledge.
The real hazard of using any current AI (Score:3)
I know a lawyer whose firm has just updated their formal policy on the use of AI. It used to be "Don't." Now, they're allowed to use one, but only if the firm higher ups have specifically approved it. There are none approved, and apparently none available that meet their requirements.
Interestingly, their issue isn't that AIs [1]make up case law [calmatters.org] (they're not overworked, and aren't idiots, so they know they would have to carefully vet anything produced), but that to be useful, the query would submit to the AI engine client information they are legally required to keep confidential, and that information will be recorded and used to create future answers for other users .
[1] https://calmatters.org/economy/technology/2025/09/chatgpt-lawyer-fine-ai-regulation/
Re: (Score:2)
real firms have private models
Re: (Score:3)
He is a Republican.
Re: (Score:3)
> DEI hires will do that.
>> He is a Republican.
DJT hires will do that.
(FTFY)
The high up the ladder, the less qualified! (Score:2)
Very rarely do you see the people at the top having the real knowledge of their field. The number of people I know in a CTO or CISO role that are qualified or educated in security matters, I actually can't name any, but I'm sure it's not 0. I've been in meetings where a CTO level person will complain that 2FA is slowing down the login process, so we need to remove it. I've been in a meeting with a CISO, where I was told (paraphrased): “Don't send PGP keys with your emails, they're scaring the clien
Trump gives a speech on the topic... (Score:2)
We have the best incompetence, frankly. Powered by AI... good old American AI. ChatGPT is not Chinese, you know... it's American. Madhu had some terrific secrets. Really terrific. And he put them on an American AI. Not a Chinese AI. Talking of China, I think I need to put tariffs on China. I buy American dishes and plates... terrific quality. Don't need any "China". Only those leftist lunatics use "China". Paper Big Mac containers for me. They're American. Terrific American food in American-mad
The AI pundits were right. (Score:4, Funny)
There's now at least one person in the world who's going to lose their job due to AI.
Re: (Score:2)
LOL. I don't have mod points right now, but for the love of the Internet, mod parent up!!!
Re:The AI pundits were right. (Score:5, Insightful)
Don't worry, he'll be replaced by an equally-unqualified sycophant.