masto.ai is one of the many independent Mastodon servers you can use to participate in the fediverse.
A general Mastodon server for all languages.

Administered by:

Server stats:

2K
active users

details how may have taken sensitive data

In the first days of March, a team of advisers from 's new Department of Government Efficiency initiative arrived at the Southeast Washington, DC, headquarters of the National Labor Relations Board.

The small, independent federal agency investigates & adjudicates complaints about unfair practices.


npr.org/2025/04/15/nx-s1-53558

NPR · A whistleblower's disclosure details how DOGE may have taken sensitive labor dataBy Jenna McLaughlin
Nonilex

stores reams of potentially sensitive data, from confidential info about employees who want to form unions to proprietary business info.

The employees, who are led by adviser & billionaire tech CEO , appeared to have their sights set on accessing the NLRB's internal systems. They've said their unit's overall mission is to review agency data for compliance with the new admin's policies & to cut costs & maximize efficiency.

But acc/to an official disclosure shared w/ & other federal overseers…, subsequent whistleblower interviews & records of internal comms, technical staff were alarmed about what engineers did when granted access, particularly when staffers noticed a spike in LEAVING the agency. It's possible that the data included sensitive info on , ongoing cases & — data that 4 experts tell NPR should almost never leave the NLRB….

& data has nothing to do w/making the govt more efficient or cutting spending.

Meanwhile, acc/to the disclosure & records of internal comms, members of the team asked that their activities not be logged on the system & then appeared to try to cover their tracks behind them, turning off monitoring tools & manually deleting records of their access—evasive behavior several experts compared to what or might do.

#law#Trump#Musk

The employees grew concerned that the 's confidential could be exposed, particularly after they started detecting suspicious log-in attempts from an IP address in [wtf?], acc/to the disclosure. Eventually, the disclosure continued, the IT department launched a formal review of what it deemed a serious, ongoing or potentially removal of personally identifiable information.

#criminal#law#Trump

The believes that the suspicious activity warrants further investigation by agencies w/more resources, like or the .

experts…fear that if the data gets out, it could be abused, including by private companies w/cases before the agency that might get insights into damaging testimony, leadership, strategies & internal data on competitors — 's among them….

It could also intimidate who might speak up about unfair labor practices, & it could sow distrust in the 's independence, they said.

The new revelations about 's activities at the labor agency come from a in the IT department of the NLRB, who disclosed his concerns to & the US Office of Special Counsel [] in a detailed report that was then provided to .

#criminal#law#Trump

Meanwhile, his attempts to raise concerns internally within the preceded someone "physically taping a threatening note" to his door that included sensitive personal information & overhead photos of him walking his dog that appeared to be taken with a drone, according to a cover letter attached to his disclosure filed by his attorney, Andrew Bakaj of the nonprofit Aid.

#criminal#law#Trump

The 's account is corroborated by internal documentation & was reviewed by 11 technical experts across other govt agencies & the private sector. In total, NPR spoke to >30 sources across govt, private sector, movement, & enforcement who had their own concerns about how & the admin might be handling sensitive , & the implications for its exposure. The following account comes from the whistleblower's ofcl disclosure & interviews w/ .

employees demanded the highest level of access, what are called "tenant owner level" accounts inside the independent agency's computer systems, w/essentially unrestricted permission to read, copy & alter ….

When an IT staffer suggested a streamlined process to activate those accounts in a way that would let their activities be tracked, in accordance with policies, the IT staffers were told to stay out of DOGE's way….

#law#Trump#Musk

For professionals, a failure to log activity is a cardinal sin & contradicts best practices as recommended by the National Institute of Standards & Technology [] & the 's , as well as the & the .

"That was a huge red flag," said Berulis. "That's something that you just don't do. It violates every core concept of security & best practice."

#criminal#law#Trump

Those are important for record-keeping requirements & allow for troubleshooting, but they also allow experts to investigate potential breaches, sometimes even tracing the attacker's path back to the vulnerability that let them inside a network. The records can also help experts see what might have been removed. Basic logs would likely not be enough to demonstrate the extent of a bad actor's activities, but it would be a start.

#law#Trump#Musk

There's no reason for any legitimate user to turn off logging or other tools, experts say.

"None of this is normal," said Jake Braun…fmr acting principal dpty natl cyber dir at the WH…. "This type of activity is why the government buys insider-threat-monitoring technology. So we can know things like this are happening & stop sensitive data exfiltration before it happens," he told NPR.

#criminal#law#Trump

However, the 's budget hasn't had the money to pay for tools like that for years, Berulis said.

A couple of days after arrived, Berulis saw something else that alarmed him while browsing the internet over the weekend.

MIT grad & DOGE engineer had been sharing info about coding projects he was working on to his public account w/ GitHub….

#criminal#law#Trump

After journalist Roger Sollenberger started posting…about the account, Berulis noticed something Wick was working on: a project, or repository, titled "NxGenBdoorExtract."

Wick made it private before Berulis could investigate further, he told NPR. But to Berulis, the title itself was revealing.

"So when I saw this tool, I immediately panicked,"…He immediately alerted his whole team.

#criminal#law#Trump

While NPR was unable to recover the code for that project, the name itself suggests that Wick could have been designing a , or "Bdoor," to extract files from 's internal case management system, known as NxGen, acc/to several experts who reviewed Berulis' conclusions.

…NxGen is an internal system that was designed specifically for the NLRB in-house, acc/to several of the engineers who created the tool….

#criminal#law#Trump

…while many of the 's records are eventually made public, the NxGen case management system hosts from competitors, personal information about members or employees voting to join a union, & testimony in ongoing cases. Access to that data is protected by numerous federal , including the Act.

#criminal#law#Trump

…engineers were also concerned by staffers' insistence that their activities not be logged, allowing them to probe the NLRB's systems & discover info about potential flaws or vulnerabilities w/o being detected.

“The whole idea of removing logging & [getting] tenant-level access is the most disturbing part to me," one engineer said.

#criminal#law#Trump

"If he didn't know the backstory, any [chief information security officer] worth his salt would look at network activity like this & assume it's a nation-state attack from or ," said Braun, the fmr White House official.

#criminal#law#Trump

About a week after arriving, the engineers left & deleted their accounts….

In the office, Berulis had had limited visibility into what the DOGE team was up to in real time.

That's partly because, he said, NLRB isn't advanced when it comes to detecting insider threats…. "We as an agency have not evolved to account for those," he explained. "We were looking for [bad actors] outside," he said.

#criminal#law#Trump

But he counted on leaving at least a few traces of its activity behind,…details he included in his ofcl disclosure.

First, at least 1 DOGE account was created & later deleted for use in 's cloud systems, hosted by Microsoft:
DogeSA_2d5c3e0446f9@nlrb.microsoft.com

Then, DOGE engineers installed what's called a "container," a kind of opaque virtual computer that can run programs…w/o revealing its activities to the rest of the network.

On its own, that wouldn't be suspicious, though it did allow the engineers to work invisibly & left no trace of its activities once it was removed.

Then, Berulis started tracking sensitive leaving the places it's meant to live…. First, he saw a chunk of data exiting the NxGen case management system's "nucleus," inside the system, Berulis explained. Then, he saw a large spike in outbound traffic leaving the network itself.

#criminal#law#Trump

@Nonilex

This whole thread is one of the reasons why I'm unable to keep my voice down when calling my Senators.

@Nonilex

Absolutely. Turning off logging and/or other computer security tools shouts that you are committing a crime. It is also destruction of govt records.

"Mientras tanto, sus intentos de plantear inquietudes internamente en la #NLRB precedieron a que alguien "pegara físicamente con cinta adhesiva una nota amenazante" en su puerta que incluía información personal confidencial y fotos aéreas de él paseando a su perro que parecían haber sido tomadas con un dron, según una carta de presentación adjunta a su declaración presentada por su abogado, Andrew Bakaj, de la organización sin fines de lucro #Whistleblower Aid."
@Nonilex

@Nonilex

This is why trump moved yesterday to defund NPR

@Nonilex considering the situation doesn't surprise me but I still want to scream at the screen.