The DOGE That Ate SSA: Inside the Data Breach Waiting to Happen

Trump’s Department of Government Efficiency put a Musk protégé with reported hacker ties in the chain of control over your Social Security data. Here’s why that’s a national security nightmare.

Share
The DOGE That Ate SSA: Inside the Data Breach Waiting to Happen

A whistleblower walks out

Charles Borges, the Social Security Administration’s Chief Data Officer, resigned “involuntarily” after blowing the whistle on a live copy of America’s most sensitive data being moved into an off‑book cloud environment steered by DOGE operatives—an environment he says circumvented standard oversight and put more than 300 million people at risk (NBC News | CBS News).

In his protected disclosure, Borges details how DOGE personnel created a shadow cloud repository with privileged access that could expose Social Security numbers, bank routing details, and the very systems that control benefit payments—warning that a compromise could trigger mass identity theft and force the government to reissue every Social Security number (Government Accountability Project PDF).

SSA’s line is that the data is “walled off from the internet” and hasn’t been compromised—but “trust us” doesn’t cut it when the whistleblower says internal controls were bypassed and leadership shut down visibility (CBS News | NBC News).


Who holds the keys? The rise of “Big Balls”

The complaint—and subsequent reporting—trace an eyebrow‑raising arc for Edward Coristine (“Big Balls”): Neuralink intern → DOGE “Senior Advisor” → GS‑15 federal employee in May 2025 (one of the highest civil‑service pay grades) → DOGE resignation in June → reappears at SSA days later (Wired | Wired).

Coristine has no known criminal convictions, but the record is replete with hacker‑community ties and security incidents: he was fired from Path Network after an alleged leak to a competitor (Gizmodo | Mediaite), and his infrastructure company DiamondCDN supported EGodly, a cybercrime group that bragged about data theft and harassing an FBI agent (Computerworld).

Investigative reporting also links Coristine to “The Com,” a cluster of Discord/Telegram communities associated with cybercrime; a Telegram handle tied to him allegedly solicited a DDoS‑for‑hire in 2022 (KrebsOnSecurity).

Add to that Tesla.Sexy LLC, which controls domains registered for the Russian market, a detail that—while not illegal—raises predictable clearance and counter‑intel questions given his placement near federal data spines (Wired).


The DOGE bench now embedded at SSA

Borges names Aram Moghaddassi—a former Neuralink/X technologist who worked with DOGE—as a central figure. He served on DOGE projects, then landed as SSA’s CIO in June/July 2025, after an interim rotation of DOGE‑aligned IT leaders (DevX | Nextgov).

Reporting shows DOGE actors, including Moghaddassi and Coristine, were previously given broad access to USCIS systems, including a cloud “data lake” and enabling tools like GitHub (FedScoop).

The Supreme Court’s emergency order in June green‑lit expanded DOGE access to SSA systems, despite union privacy challenges—setting the stage for the very off‑platform handling Borges describes (The Hill).


Not just theoretical risk: there’s already a misuse case

This isn’t merely a “what if.” Earlier this year, SSA data was reportedly weaponized to target immigrants—with thousands of migrants flagged as “dead” to prompt “self‑deportation,” according to contemporaneous reporting, and with minors included on a high‑risk list sent to SSA leadership, calling the underlying data hygiene and claims into question (New York Times | New York Times).

Pair that track record with Borges’s allegation of a live copy of the Numident (the backbone record of every SSN) moved into a DOGE‑controlled cloud enclave with weak auditability, and the risk calculus is plain: a single point of catastrophic failure (Government Accountability Project PDF).


What happens if that enclave is abused or breached

If a misconfiguration, insider misuse, or intrusion occurs, attackers (or rogue operators) could change direct‑deposit instructions, freeze benefits, or drain linked accounts before agencies even recognize what happened. At scale, you could trigger mass identity theft and the logistical nightmare of re‑issuing identifiers to an entire nation (Government Accountability Project PDF | CBS News).

SSA says the data is “walled off,” but the complaint says oversight was sidelined and requests for visibility were ignored or rebuffed—including reports of staff being told not to answer the CDO’s queries (NBC News | The Handbasket).


From CDC to SSA: the pattern is governance collapse

This is part of a broader story: institutional hollowing. The CDC director, Susan Monarez, was pushed out weeks into the job, followed by senior resignations over vaccine policy and the “weaponization of public health” (STAT | POLITICO). Public health leaders described chaotic directives and retaliatory culture (The Guardian | Advocate).

Now that same blend of political speed, improvised authority, and disdain for guardrails is being applied to the Social Security data spine, which underwrites Americans’ identity, benefits, and financial security.


What needs to happen now

The public doesn’t need platitudes about “efficiency.” We need verifiable controls.

  • Extract and quarantine: Remove any live copy of SSA production data from unaccredited environments; store only in accredited enclaves with FISMA‑aligned controls and validated A&A.
  • Re‑establish chain of command: Restore standard segregation of duties, least‑privilege access, and independent logging under agency authority; immediately revoke unfettered access for non‑cleared, non‑agency personnel.
  • Independent technical audit: Commission a NIST‑aligned red/blue‑team assessment and configuration review, reporting directly to IG/GAO and relevant Hill committees.
  • Congressional guardrails: Codify limits on third‑party access to systems of record and PII data lakes, and require public inventorying of any copy operations involving SSN‑bearing datasets.

Anything less leaves 300+ million Americans a misstep away from chaos.


For readers who want the receipts