Skip to content
Hugin
A blank sheet on a dark desk above an open drawer filled with papers.

Hugin News

GAO could count DOGE-accessible systems. It could not establish the permissions.

1 min read

Original editorial artwork from the Hugin archive; symbolic records illustration.

A September 29 review of six agencies found incomplete access and security-control records. Four reported access to more than 23 systems containing sensitive information. The finding is a gap in assurance—not proof of a breach.

governmentprivacycybersecurityaccountability
1source receipts1source hosts1 minread timelinkedprimary source

Knowing that a team had access to a system does not establish what each member could do inside it.

GAO's September 29 review covers DOGE teams at six federal agencies. CFPB, Education, NOAA and SEC collectively reported access to more than 23 systems holding sensitive information. GAO could not determine particular permissions, including whether members could view personal information or modify data. SBA and VA did not provide the requested system-access information.

Where the assurance breaks down

CFPB, Education and SEC provided limited control documentation. NOAA, SBA and VA did not respond to requests about controls. GAO concludes that Congress and the public lack assurance that the reviewed agencies implemented the necessary safeguards.

That conclusion does not establish that a breach occurred. It identifies what the review could not verify.

The response

CFPB raised concerns about the report's accuracy; GAO says it stands by its facts. The other five agencies said they had no comments on the draft.

Source links