Data Security

Federal Investigators Say Certain DOGE Records Were Deleted

A federal IT staffer filed a whistleblower complaint alleging that members of the Department of Government Efficiency (DOGE) had accessed sensitive information from the National Labor Relations Board (NLRB). Following this complaint, a subsequent report by the Government Accountability Office (GAO) noted that DOGE team member accounts with system access had been deleted shortly before investigators could observe them. This deletion obscured digital records of DOGE’s access, leaving the GAO unable to definitively confirm the extent of their activities or the level of access granted. The NLRB, which handles sensitive information related to whistleblowers, trade secrets, and labor disputes, has seen its data access records compromised.

Read More

France Leads Europe in Tech Sovereignty Amidst Palantir Exit Push

France’s domestic intelligence agency is in the process of replacing U.S. firm Palantir with French company ChapsVision, a move that signals a wider European push for technological sovereignty. This transition, prompted by security needs that first led to the adoption of Palantir’s platform after the 2015 Paris attacks, aims to reduce reliance on American technology. The shift is part of France’s broader strategy to develop domestic AI capabilities, mirrored by similar moves in Germany and ongoing debates in the UK regarding dependence on U.S. platforms. While this effort seeks to bolster European technological independence, some experts warn against premature abandonment of proven U.S. systems due to potential capability gaps in emerging European alternatives.

Read More

23andMe Victims Deserve $46.75 Million Payout Amidst Data Breach Fallout

It appears that victims of the significant 23andMe data breach might finally see some financial restitution, with a bankruptcy administrator now suggesting that a payout of $46.75 million is warranted. This development follows 23andMe’s filing for protection from creditors in March 2025, a move attributed, in part, to the fallout from the data breach and the ensuing litigation, alongside other business pressures.

The scale of the data breach itself has been a point of much discussion, with estimates suggesting that genetic and other personal information of approximately 6.9 million U.S. customers were exposed. While the initial headlines might have painted a picture of widespread, direct DNA sequence compromise for millions, the reality appears to be more nuanced.… Continue reading

UK Grants Palantir Unlimited NHS Patient Data Access Amidst Major Breach Concerns

The NHS is reportedly set to grant “unlimited access” to identifiable patient data to staff from companies, including Palantir, involved in developing its federated data platform. This change, detailed in an internal briefing, would allow external engineers, such as those from Palantir and consultancy firms, to access the National Data Integration Tenant (NDIT) with an “admin” role. This marks a departure from current protocols, which require individual data access approvals for specific datasets. While the NHS maintains strict data management policies and security clearances for external personnel, the briefing acknowledges a potential “risk of loss of public confidence” regarding patient data safeguarding due to these enhanced permissions. Recommendations within the document suggest limiting the number and duration of these external admin roles.

Read More

Half a Million Britons’ Medical Data for Sale on Chinese Website

The concerning news that the medical data of half a million Britons has been found listed for sale on a Chinese website has understandably sparked a great deal of apprehension, particularly as we navigate an increasingly digital world where personal information is a valuable commodity. The very notion of sensitive health details being treated as a product for sale is deeply unsettling, highlighting the inherent risks associated with the digitization of our most private information. This situation raises critical questions about data security, accountability, and the ethical implications of how our personal information is handled.

The selling of such data is demonstrably profitable, creating a strong incentive for malicious actors to acquire and exploit it.… Continue reading

Social Security Data Breach Sparks Outrage Over Alleged Pardon Expectation

A former DOGE software engineer, allegedly embedded within the Social Security Administration, is accused of exfiltrating databases containing records of over 500 million Americans on a thumb drive. This individual reportedly informed colleagues that he possessed sensitive citizen data and expected a presidential pardon if his actions were deemed illegal. This incident is part of a pattern of alleged data mismanagement and overreach by DOGE operatives within federal agencies, raising significant privacy and security concerns.

Read More

IRS Improperly Disclosed Immigrant Tax Data to DHS

The U.S. Internal Revenue Service has reportedly engaged in an improper disclosure of confidential tax information belonging to thousands of individuals to federal immigration enforcement authorities. This significant breach, as detailed by the Washington Post and corroborated by sources familiar with the matter, suggests a serious lapse in the safeguarding of sensitive taxpayer data. The IRS is said to have recently uncovered this error and is now collaborating with other federal agencies to address the fallout from this disclosure.

The implications of such a disclosure are far-reaching and raise substantial questions about the integrity of taxpayer privacy and the government’s ability to protect confidential information.… Continue reading

Trump’s Cyber Security Head Uploads Sensitive Materials to ChatGPT

A recent report reveals that Madhu Gottumukkala, the head of the Cybersecurity and Infrastructure Security Agency, uploaded “sensitive” contracting materials to a public version of ChatGPT, triggering an internal review. The documents, marked “for official use only,” were not classified but were considered sensitive and should not have been released publicly, which triggered automated alerts. Despite Gottumukkala having special permission to use ChatGPT, the incident prompted a review by top DHS officials to assess potential harm, with the results still unknown. This event occurred amid the widespread adoption of AI in the workplace, highlighting the increasing need for careful handling of sensitive information.

Read More