menu
techminis

A naukri.com initiative

google-web-stories
source image

Krebsonsecurity

7d

read

266

img
dot

Whistleblower: DOGE Siphoned NLRB Case Data

  • A security architect at the NLRB alleges that DOGE employees transferred sensitive data in March using short-lived accounts configured to leave few traces.
  • The data outflows coincided with blocked login attempts from a Russian internet address using valid credentials.
  • The whistleblower's letter was sent to the Senate Select Committee on Intelligence.
  • The NLRB is an independent agency that investigates unfair labor practices and stores sensitive data.
  • DOGE officials demanded powerful 'tenant admin' accounts exempt from detailed logging activity.
  • The new DOGE accounts had unrestricted access to NLRB databases and the ability to alter information.
  • One DOGE account created a virtual environment and transferred approximately 10 gigabytes of data from the NLRB's system.
  • Numerous login attempts from a Russian IP address using correct credentials for a DOGE account raised alarm.
  • The NLRB launched an investigation but was instructed to drop it, prompting the whistleblower to go public.
  • Claims of network anomalies, missing logs, and unauthorized code library downloads further raised suspicions.

Read Full Article

like

16 Likes

For uninterrupted reading, download the app