Notes from a March 18 meeting, marked “Internal/Confidential,” amusement that a DOL lawyer presented colleagues with an overview of DOL’s interactions with DOGE. “So far,” the notes read, “they bash not person constitute access. They person asked; we’ve held them astatine bay. We’ve tried to get them to archer america what they privation & past we bash it. They lone person work access.” DOGE seems chiefly interested, according to the notes, successful wage systems and grants, and has signed an statement detailing a “long database of things they won’t do.”
The notes besides item interactions betwixt the GAO and DOL related to DOGE’s work. Included are a circumstantial acceptable of requests GAO gave to DOL representatives:
“Please place immoderate systems and accusation for which USDS and/or bureau DOGE squad unit were provided access. In doing so, delight place each accounts created, including those for immoderate applications, servers, databases, mainframes, and/or web equipment.
“Please picture the benignant of entree that USDS and/or bureau DOGE squad unit person to bureau systems and accusation (e.g., read, write, execute).
“Please picture however USDS and/or bureau DOGE squad unit entree bureau systems and accusation (e.g., on-premise oregon remote, bureau furnished instrumentality oregon different equipment).
“Please picture the safeguards that are successful spot to find that USDS and/or bureau DOGE squad unit support the confidentiality, integrity, and availability of bureau systems and accusation accordant with applicable laws and guidance.
“Please picture the processes that the bureau has successful spot to guarantee that USDS and DOGE teams are appropriately protecting the confidentiality, integrity, and availability of the bureau systems and accusation arsenic required by applicable laws and guidance?”
Concerns astir DOGE entree to bureau systems are not unfounded. In February, WIRED reported that Marko Elez, a 25-year-old erstwhile X engineer, was granted the quality not lone to work the codification successful the Treasury systems but besides to write—or change—it. With that level of access, determination were concerns that helium could person perchance chopped disconnected congressionally authorized payments oregon caused the systems to simply halt working. “It’s similar knowing you person hackers connected your network, but cipher lets you bash thing astir it,” a Treasury worker told WIRED astatine the time.
Elez, according to the March 18 gathering notes and erstwhile WIRED reporting, besides has entree to the DOL and has been linked to the Social Security Administration. His and different DOGE affiliates’ entree to SSA information is presently restricted owed to a tribunal order. Elez did not instantly respond to a petition for comment.
Reporting from WIRED and different outlets since past has continued to exposure DOGE’s sweeping attempts to entree delicate data—and the imaginable consequences. President Donald Trump’s enforcement bid from March 20 directs agencies to statesman “eliminating accusation silos,” purportedly to combat fraud and waste. These actions could besides endanger privateness by consolidating idiosyncratic information housed connected antithetic systems into a cardinal repository, WIRED antecedently reported.
A grounds detailing an archetypal petition from GAO for DOL documents, owed astatine the extremity of March, shows that the bureau was asked to amusement however it protected its systems, with the requested documentation covering, among different things, its policies connected absorption of entree to strategy accounts, training, the principles of separation of duties and slightest privilege, the usage of portable retention devices, audit logging, and its insider menace program. These requests notation the National Institute of Standards and Technology work Security and Privacy Controls for Information Systems and Organizations, which serves arsenic a acceptable of accusation information guidelines for national systems not related to nationalist security.