TL;DR: Elon Musk’s Department of Government Efficiency barged into at least 10 federal agencies and accessed the personal data of hundreds of millions of Americans: Social Security numbers, tax returns, biometric records, medical histories, and background checks. At least 12 federal lawsuits say this violated the Privacy Act of 1974. Multiple judges agreed, issuing injunctions and restraining orders. Then the Supreme Court overruled them 6-3, handing DOGE the keys to Social Security’s master database of 300+ million records. A whistleblower says DOGE copied that data to an unauthorized cloud server. The agency that owns the data can no longer access it.
12 Lawsuits and Counting
Since January 2025, at least 12 federal lawsuits have been filed alleging DOGE violated the Privacy Act of 1974, the law that says the government can’t share your personal records between agencies without your consent or a specific legal exception.[1]
The plaintiffs include labor unions, privacy nonprofits, state attorneys general, individual federal employees, and ordinary taxpayers. The defendants: Musk, DOGE, OPM, Treasury, SSA, and half the federal government.
Here’s a sampling of the key cases:
- Alliance for Retired Americans v. Bessent (D.D.C., Feb. 3, 2025): seeking to block DOGE access to Treasury databases
- EFF/Lex Lumina v. OPM (Feb. 11, 2025): demanding a halt to OPM disclosing millions of Americans’ sensitive data to DOGE
- Gribbon v. Musk (D.D.C., Feb. 12, 2025): class action on behalf of taxpayers, federal employees, and benefits recipients seeking compensation for DOGE’s unauthorized access
- AFSCME v. SSA (D. Md., Feb. 21, 2025): blocking DOGE access to Social Security databases
- 14-State Attorney General lawsuit (D.D.C., Feb. 2025): challenging Musk and DOGE on constitutional Appointments Clause and statutory authority grounds[2]
- CREW v. U.S. DOGE Service: demanding transparency on DOGE’s activities under open records laws[3]
NBC News documented 11 cases focused specifically on data and privacy by early 2025.[1] More have followed.
Judges Fought Back. Then Got Overruled.
At least five federal judges tried to slam the brakes on DOGE’s data grab. They all had the same basic reaction: this is illegal.
- Judge Paul Engelmayer (S.D.N.Y.): issued a temporary restraining order on February 8, 2025, blocking DOGE from accessing Treasury material
- Judge Jeannette Vargas (S.D.N.Y.): issued a preliminary injunction on February 21, 2025, barring anyone affiliated with DOGE from accessing federal payment systems. She called DOGE’s process “chaotic and haphazard” and noted the systems contain “names, Social Security numbers, birth dates, birth places, home addresses and telephone numbers, email addresses, and bank account information”[4]
- Judge Colleen Kollar-Kotelly (D.D.C.): limited DOGE to “read-only” access at Treasury
- Judge Denise Cote (S.D.N.Y.): granted a preliminary injunction blocking DOGE from OPM databases, finding a “strong likelihood” of Privacy Act violations[5]
- Judge Ellen Hollander (D. Md.): ruled plaintiffs were likely to succeed on claims that SSA giving DOGE access to millions of records violated the Privacy Act
Five judges. Five variations of “this is probably illegal.”
Then the Supreme Court weighed in.
On June 6, 2025, in SSA v. AFSCME, the conservative majority ruled 6-3 to overturn the lower court restrictions and restore DOGE’s access to Social Security data. Justices Kagan, Sotomayor, and Jackson dissented, noting the government had shown no need for the data and no interest in complying with privacy safeguards.[6]
The dissenters wrote that the court had granted “emergency relief that allows the Social Security Administration to hand DOGE staffers the highly sensitive data of millions of Americans” despite the government’s “failure to show any need or any interest in complying with existing privacy safeguards.”
What DOGE Actually Accessed
Across at least 10 federal agencies, DOGE personnel gained access to data that most Americans assume is private:
Treasury Department
SSNs, tax returns, home addresses, birth dates, bank account info, and federal payment records covering trillions in transactions.
Social Security Administration
The NUMIDENT master file: SSNs for 300+ million Americans, names, birth dates/places, citizenship, race/ethnicity, parents’ names.
Office of Personnel Management
Background checks, medical records, bank account info, biometric data, fingerprints, facial recognition data for federal employees.
Other Agencies
IRS (tax returns), CMS (health data), Veterans Affairs (military and mental health records), Education (student loan data), DHS (immigration verification), CFPB (financial data).
At least one DOGE employee had temporary edit access at Treasury, meaning they could change or delete federal payment records, not just read them.[4]
DOGE even published National Reconnaissance Office budget and staffing data on their public website. NRO is one of the most secretive intelligence agencies in the country.
The Whistleblower: “The Business Need Is Higher Than the Security Risk”
On August 26, 2025, Chuck Borges, the chief data officer at the Social Security Administration, filed a written complaint through the Government Accountability Project.[7]
His allegations:
- On June 10, 2025 (just four days after the Supreme Court ruling), a former DOGE employee requested SSA copy its NUMIDENT database. That’s the master file for every Social Security card ever issued.
- Aram Moghaddassi, a DOGE-affiliated hire who became co-chief information officer at SSA, authorized the copy. His stated rationale: “I have determined the business need is higher than the security risk.”
- The data (covering 300+ million Americans) was placed on an unauthorized Cloudflare server, outside SSA’s control.
- Borges, the chief data officer, was not informed of or consulted on the transfer.
- SSA can no longer access the server where its own data now sits.[8]
Borges resigned on August 29, 2025. Three days after filing the complaint.
On March 3, 2025 (months before the NUMIDENT copy), a DOGE team member had already sent an encrypted file with names and addresses of roughly 1,000 people to DHS, copying DOGE adviser Steve Davis. SSA’s Chief Information Officer couldn’t even access the file to see what was in it.[7]
SSA’s own January 16, 2026 court filing corrected prior statements, admitting DOGE had wider access than previously disclosed and that data had been transferred to a non-SSA server the agency can no longer reach.[8]
“One Big Beautiful Database”
This isn’t random. It’s a plan.
In March 2025, Trump signed an executive order titled “Stopping Waste, Fraud, and Abuse by Eliminating Information Silos”, directing agencies to share data across the government. Brookings called the result what it is: an attempt to build “one big, beautiful database” of Americans’ most sensitive information.[9]
Who’s building it? Palantir, the surveillance contractor co-founded by Peter Thiel. At least three DOGE members previously worked at Palantir. Two others came from Thiel-funded companies.[9]
The Brookings analysis draws a direct line to DARPA’s Total Information Awareness (TIA) program, the post-9/11 surveillance proposal that would have combined communications, financial, education, travel, and medical records into a single system. Congress killed TIA in 2003 because the privacy implications were too extreme.
DOGE is building something similar. The difference: this time, they didn’t ask Congress.
And some of the security controls are gone. DOGE staffers gained the ability to add new accounts and disable automated tracking logs at several Cabinet departments. Many agencies no longer create records of who accessed or changed information.[9]
The Fraud They Actually Found
DOGE justified all of this as fighting waste and fraud. So how did that go?
DOGE implemented phone-claim checks at SSA that flagged exactly 2 of 110,000 claims as potentially fraudulent. A 0.002% hit rate. Meanwhile, the checks slowed retirement claim processing by 25%.[7]
EPIC described DOGE’s data access as potentially “the largest and most consequential data breach in U.S. history.”[10]
For context: the 2015 OPM hack affected 22 million people and led to widespread identity theft. DOGE now has access to the same databases, plus dozens more.[11]
What Happens Now
The lawsuits are still moving through the courts. In April 2026, the Fourth Circuit vacated a lower court’s preliminary injunction on SSA data access, ruling plaintiffs hadn’t shown irreparable harm was likely. Judge Toby Heytens wrote the opinion, but even he called the whistleblower revelations about DOGE data misuse “even more alarming.”[12]
“Even more alarming.” And still not enough to stop it.
The Privacy Act was written in 1974 to prevent exactly this: the government merging databases to build comprehensive profiles of every citizen. Fifty years later, a handful of Silicon Valley engineers with temporary badges are doing it anyway, and the courts keep letting them.
Meanwhile, the data sits on a server the Social Security Administration can’t access, managed by people who used it to check voter rolls for a political advocacy group on March 24, 2025.[7]
DOGE calls it efficiency. Twelve lawsuits call it a crime. The Supreme Court calls it fine.
What You Can Do
- Freeze your credit at all three bureaus (Equifax, Experian, TransUnion). It’s free and it’s the single best defense against identity theft from leaked SSNs.
- Monitor your Social Security account at ssa.gov/myaccount. Look for unauthorized changes or claims.
- Use the IRS Identity Protection PIN at irs.gov. Prevents anyone from filing a tax return in your name.
- Contact your representatives. The ACLU’s Keep DOGE Out of Our Data campaign makes it easy.
References
- NBC News: DOGE lawsuits: 11 cases about Musk group focus on data, privacy (2025)
- Axios: Judge allows lawsuit by 14 states against Elon Musk and DOGE to proceed (May 28, 2025)
- CREW: CREW sues U.S. DOGE Service to compel transparency
- Courthouse News: Federal judge extends order barring DOGE from Treasury payment system
- EFF: Judge rejects government’s attempt to dismiss EFF lawsuit against OPM, DOGE, and Musk
- NPR: Supreme Court grants DOGE access to confidential Social Security records (June 6, 2025)
- Government Accountability Project: Chuck Borges Whistleblower Disclosure (August 26, 2025)
- NPR: Trump administration admits even more ways DOGE accessed sensitive personal data (January 23, 2026)
- Brookings: Privacy under siege: DOGE’s one big, beautiful database
- EPIC: EPIC v. OPM: DOGE Privacy Violations
- Harvard Ash Center: Understanding DOGE and Your Data
- Nextgov: Appeals court removes limits on DOGE access to SSA data despite “alarming” revelations (April 2026)