Navigated to DOGE put Social Security numbers on cloud server at risk of hacking - Transcript

DOGE put Social Security numbers on cloud server at risk of hacking

Episode Transcript

Hey everybody, welcome back to the Elon Musk Podcast.

This is a show where we discuss.

The Critical.

Crossroads, the Shape, SpaceX, Tesla X, The Boring Company and Neurolink.

I'm your host, Will Walden.

A former Trump campaign aide A former Trump campaign aide is at the center of a federal data breach that leaks Social Security numbers of over 200,000 Americans, raising urgent questions about how a meme, a cryptocurrency project, gained access to sensitive government systems.

Now the breach involves Doge Labs, a little known crypto startup run by Tommy Rensing, who previously worked for Donald Trump's 2020 campaign in digital strategy.

Doge Labs had a contract with the US government to run a bot detection system under the pretense of helping federal agencies track misuse of public benefits.

Instead, the company allegedly mishandled the personal data with Social Security recipients, exposing it in a breach that took place over several months.

Federal investigators found that Social Security numbers, birth dates, addresses and benefit payment details or accessible through an unsecured interface connected to Doge Labs back end system.

The briefs didn't stem from a malicious attack at all, but from severe misconfigurations and how the system handled and stored sensitive data.

Americans sensitive personal data.

You should be mad about this.

Your Social Security number, your birthday, your address and benefit payment details could have been leaked by these unprofessional people.

There are rules for a purpose.

Doge Labs reportedly left a staging server online without basic access controls.

Anyone with the URL could scrape the data in bulk.

I've set up staging servers before for clients.

Could be an AWS server, it could be any other cloud service.

We're not sure where it was at this point, but we're going to dig into this and we're going to let you know exactly what happened.

But Doge Labs secured the contract through a pilot program designed to bring innovative tech startups into federal service procurement pipelines.

The program fast tracked vendors who could demonstrate AI and machine learning capabilities and renting pitch.

Doge Labs is a tool that can detect fraudulent behavior in benefit claims using blockchain based identity scoring.

The government bought the idea without fully vetting the system's infrastructure or compliance with data protection protocols, and the exposure affected data from at least three federal agencies, Social Security, the Department of Health and Human Services, and the Department of Veterans Affairs.

3 absolutely important agencies.

All three used DOGE Lab software as a part of an experimental fraud prevention initiative launched in 2023.

Internal emails reviewed by investigators show the concerns about Doge Labs data handling practices were raised as early as May, but federal tech officers dismissed the warnings as over cautious.

Tommy Rensing has denied wrongdoing.

It claims that no actual data was stolen.

He described the system as safe and secure and said any exposure was due to a minor miscommunication between subcontractors that contradicts federal findings that the data was not only accessible but also downloaded by outside parties over a period of five weeks before the server was taken offline.

No details about these outside parties who has downloaded it, but they did it over 5 weeks.

They have all of your data now.

If you think that's not important or you're just going to miss push that to the side, that's on you.

But your Social Security number, your benefits, VA, etcetera were all exposed due to this DOGE subcontractor.

The government has not publicly confirmed how many people were affected, but an internal audit found 212,415 Social Security records had been exposed.

212,000 people at Social Security numbers have been exposed and downloaded for five weeks straight.

Most of the individuals are recipients of Medicare, disability or VA benefits.

The breach impacted elderly and low income Americans more so than anybody else.

Several civil rights groups were preparing lawsuits, as they should, and demanding answers about why a crypto startup but no public track record was entrusted with such sensitive federal systems.

Now, mind you, I'm a reporter.

I'm neither here nor there.

I'm right down the middle and I call it like it is.

If these people messed with your Social Security numbers or messed with your VA benefits, they did something absolutely wrong.

Absolutely.

And they should feel the wrath of all these lawsuits because you know what?

It's not about left or right.

It's not about your stupid politics at this point, any politics.

This is about people stealing trustworthy Americans data because they were they were unsecure in their ways of doing business.

Doge Labs.

How dare you.

How dare you.

A staging server, Really A public date staging server where anybody with the URL could scrape your data.

It takes about 10 minutes to create a scraping bot if you have the URL to a a website and also if you have a URL to a website where all the data is out there in the open.

If you have a link, literally all you need to do for some instances is control all control a control copy, put it into a spreadsheet, control paste and run it through chat TBT, see if you can get any great data out of it.

And if you can, that's good for the hackers that did this, that hacked into the system.

You know what hackers will hack and these people should have been absolutely secure with your data.

This is your data, Americans.

These people at Doge Labs did you dirty.

I want you to know that sometimes I get up in arms about some stuff.

Stealing people's data, stealing people's sensitive veteran data.

If you're a true American, if you're a patriot, you have to support the veterans.

Everybody should support veterans anyway.

They've done some crazy stuff in their life.

They've, they've sacrificed a lot so we can stay free.

So these people mess with veterans.

They should get messed with too.

In of court, of course, court and legal battles.

But this isn't the only controversy surrounding Doge Labs right now.

According to documents viewed by The Telegraph, the company used the same infrastructure to promote a meme coin campaign that launched just weeks before the breach was discovered.

OK, so the DOE, the Dogecoin derivative token which is DOGE dot Fed, was hyped on social media as a pro Trump financial movement, with rensing using his campaign connections to attract far right influencers and fringe candidates.

Several of those promotions included footage filmed at federal offices, which may violate ethics laws around commercial activity on government property.

Come on man, this Rensink.

Come on man you are a clown.

Why do you OK now?

The timing has raised questions about whether Rensink used his government access for personal or political gain.

Looks like a little bit of both.

You registered, dodged out feds smart contract.

Just 10 days before he began the government pilot, he directed internal staff to use government funded servers for performance testing of the crypto token.

Government funded servers for his own personal crypto token.

This guy needs to get audited.

Need to mess with him in court.

I got to get him.

Those servers were later identified as the source of this data exposure too.

So anybody with access to these crypto coins and to test them, anybody should be questioned and they should be held accountable if they did anything wrong.

Now, federal, federal fallout from the breach is already hitting Capitol Hill.

Congressional aides confirm that Senate Democrats are preparing hearings into how the contract was awarded and what safeguards have failed.

Some Republicans have also expressed concerns over the lack of oversight and tech contracting, though Trump allies have attempted to distance the former president and current president from rensing, calling him a volunteer with limited responsibilities.

OK, so we all know that's not true.

Limited responsibilities.

Don't think that's true if you have access to Social Security numbers.

That's not a limited security and lot limited authority, not limited responsibilities.

You are absolutely not a volunteer if you have access to Social Security numbers.

Now.

The scandal also comes as Trump intensifies calls to gut the federal workforce.

Now, at a rally this weekend, he praised Rensing's push for private innovation and said federal agencies should move fast and break things when dealing with fraud.

Just like Silicon Valley, man, he's taking a play, a play out of, you know, a Meta.

And all the Silicon Valley elites that I used to work for back in the day don't like him anymore.

By the way, I like code.

I like creating things.

But Silicon Valley, it was a long time ago.

Trump also proposed eliminating entire agencies like the Department of Education and the EPA to fund a new AI and crypto task force that would partner directly with private firms.

Now, that approach echoes the kind of low accountability contracting that allowed Doge Labs to slip through our fingers.

Now the offense of Management and Budget issued an immediate suspension of all contracts issued under the same tech pilot that approved Doge Labs.

The White House also ordered a full review of every agency that uses third party AI for fraud prevention or citizen data handling.

That review will likely result in stricter federal tech procurement standards and data access audits for existing contractors.

Now Those Labs has deleted its website.

It disabled all public phasing services, right?

Singh is reportedly preparing a launch of a legal defense fund, arguing that the breach is being politicized ahead of 2026 midterms.

Meanwhile, affected users have begun receiving breach notifications, with some reported fraudulent activity on their credit reports within weeks of the leak.

Wow, this is a horrible situation.

How dare they do this to veterans and other people, people that don't have much.

What?

OK, I'm going to say it.

What a scumbag.

What a loser.

Let me know what you think in your podcast comments because this is a this is a dirty one.

This is a dirty one.

Let me know what you think.

All right.

Take care, everybody.

Hey, thank you so much for listening today.

I really do appreciate your support.

If you could take a second and hit the subscribe or the follow button on whatever podcast platform that you're listening on right now, I greatly appreciate it.

It helps out the show tremendously and you'll never miss an episode.

And each episode.

Is about 10 minutes or less to get you caught up.

Quickly and.

Please, if you want to support the show even more, go to.

Patreon.com slash.

Stage 0 and please take care of yourselves and each other and I'll see you tomorrow.

Never lose your place, on any device

Create a free account to sync, back up, and get personal recommendations.