Washington, D.C. — A senior federal official has filed a whistle-blower complaint alleging that one of the most sensitive databases in the United States — containing the Social Security numbers, names, addresses, and birthdates of every American — was uploaded to a vulnerable cloud server by a Trump-era agency built with Elon Musk’s allies.
The disclosure, made by Charles Borges, the Social Security Administration’s chief data officer, warns that the actions of the Department of Government Efficiency (DOGE) created “enormous vulnerabilities” with potentially catastrophic impact on Americans’ financial and personal security.
—
The Database That Should Never Leave the Vault
At the heart of Borges’s complaint is the Numident file, a central register of every Social Security number ever issued. More than 548 million records reside within it, making it one of the richest targets imaginable for identity thieves or hostile governments.
According to Borges, DOGE members — many of them young software engineers recruited through Musk’s companies X and Neuralink — copied the entire file to an internal “virtual private cloud” server in June. Critically, they bypassed the independent security monitoring normally required for such a sensitive move.
“There were no verified audit or oversight mechanisms,” Borges wrote. “Should bad actors gain access to this environment, Americans may be susceptible to widespread identity theft … and the government may be responsible for reissuing every American a new Social Security number at great cost.”
—
Ignored Warnings
Internal emails included in the complaint show that senior security officials inside SSA flagged the project as “high risk.” On June 16, acting chief information security officer Joe Cunningham warned DOGE leadership that the request carried serious dangers.
Nonetheless, within days, DOGE-aligned executives signed off. In one blunt memo, SSA’s Chief Information Officer Aram Moghaddassi — formerly an executive at Musk’s firms — wrote:
“I have determined the business need is higher than the security risk associated with this implementation and I accept all risks.”
—
Why DOGE Wanted the Data
What DOGE hoped to achieve remains unclear. Borges wrote that he was told the project was meant to “improve the way the agency exchanged data with other parts of government.”
But privacy advocates point to a more troubling backdrop. The Trump administration has repeatedly argued that Social Security records need to be scoured for “fraud” as part of its mass deportation agenda. Critics fear the Numident data could be cross-matched with immigration databases to target undocumented or even naturalized residents.
—
The Musk Factor
DOGE itself was born out of Elon Musk’s short-lived but turbulent stint in Washington. Although Musk has since split with Trump, many of his appointees remain in the federal bureaucracy. Borges’s complaint cites 19-year-old software engineers being given sweeping access to data that career officials themselves could not monitor.
The move came just weeks after the Supreme Court cleared the way for DOGE to access SSA data, overturning a lower-court block imposed in March.
—
The Risks
Experts say a breach of the Numident database would dwarf any prior U.S. cybersecurity incident. Unlike passwords or credit cards, Social Security numbers are foundational identifiers — often tied for life to financial accounts, medical records, and government benefits.
“Reissuing hundreds of millions of new Social Security numbers would be a logistical nightmare,” said Andrea Meza of the Government Accountability Project, which filed Borges’s complaint with Congress. “It would undermine trust in government systems and cost billions, if not trillions.”
Already, government watchdogs are warning that if identity thieves gain access, victims could lose vital health care, food benefits, and housing.
—
Political and Legal Fallout
The White House has not commented on the complaint. Nor has the Social Security Administration. But Democrats on Capitol Hill are already demanding hearings, calling the revelations “an unprecedented risk to the American people.”
The ACLU, which previously sued to block DOGE’s access, said the whistle-blower’s complaint proves their worst fears. “This is not efficiency — it is recklessness,” one lawyer said.
Borges, a 22-year Navy veteran and longtime public servant, wrote that he was deliberately excluded from meetings and left to “piece together evidence after the fact.” He turned to whistle-blower law protections only after agency lawyers instructed staff not to answer his inquiries.
—
For now, Borges has not alleged that the database was breached. But the danger, he insists, is not hypothetical. With America’s most sensitive identity records sitting on a server beyond proper oversight, the line between national security and national catastrophe has never looked thinner.
As one senior official wrote in an internal risk memo: “Sensitive data could be made public.”
For hundreds of millions of Americans, the stakes could not be higher.
