DOGE Engineers and the National Labor Relations Board: What DOGE knew before Congress and what it could have learned from NPR’s interview with Berulis
IT employees at an independent agency became worried when advisers from the Department of Government Efficiency arrived, according to a declaration filed with Congress and shared with NPR.
Unfair labor practices can be investigated by the National Labor Relations Board. Its databases have reams of confidential data about employees who want to form unions, as well as proprietary business information.
Doge’s intentions with regard to the data are unclear. Many of the systems DOGE embedded itself in across the rest of the government have employment data that can be used to evaluate grants and programs.
The IT team had little insight into the activities of the DOGE engineers. “We had no idea what they did,” he explained. His official disclosure reflects those conversations.
The labor law experts interviewed by NPR fear that if the data gets out, it could be abused, including by private companies with cases before the agency that might get insights into damaging testimony, union leadership, legal strategies and internal data on competitors — Musk’s SpaceX among them. They believe it could sow distrust in the NLRB’s independence and intimidate whistle blowers who speak up about unfair labor practices.
After DOGE staffers descended on federal buildings across Washington, Trump issued an executive order urging increased data sharing “by eliminating information silos” in a bid to give the engineers more cover to access and amalgamate sensitive federal data.
The acting press secretary for the National Labor Relations Board said the agency did not allow DOGE access to its systems. The agency conducted an investigation after Berulis raised his concerns and they found no violation of agency systems.
How Don’t You Get What You Want: A Technical Consultant’s Journey Across the NLRB “Solves a Culture of Fear”
He took the machine apart toFIGURE out how it works, just like he used to do with the radios from the thrift store. “I electrocuted myself once,” he recalled.
A knee injury prevented him from joining the military. He worked for the local rape crisis hotline while serving as a volunteer firefighter, and he gave his time as a volunteer firefighter back to the hotline. But, he told NPR, “I had an interest in serving my country.”
Berulis had been a technical consultant for many years, including in auditing and modernizing corporate systems, when a job opened up at the National Labor Relations Board.
While he didn’t know much about the agency, Berulis quickly found its mission to protect employees’ rights in line with his long-standing desire “to help people.”
He started six months before President Trump was inaugurated for a second term. Berulis said he began to secure the cloud-based data server and reinforce the principles of “zero trust”, which means users cannot get access to the parts of the system they need in order to do their jobs. That way, if an attacker gets hold of a single username and password, the attacker can’t access the whole system.
“When I first started, it was a dream come true,” he said. There was a chance to do some good. He said there was a culture of fear around the agency after the inauguration.
Source: A whistleblower’s disclosure details how DOGE may have taken sensitive labor data
The Berulis-Wick Backdoor: Detecting Cyberattacks on the DOE’s Computer Systems with a Key Person’s User Logs
The building security let the DOGE staffers in after Berulis and several colleagues saw a black SUV enter the garage. They interacted with a small number of staffers, never introducing themselves to most of the IT team.
Berulis says he was told by colleagues that DOGE employees demanded the highest level of access, what are called “tenant owner level” accounts inside the independent agency’s computer systems, with essentially unrestricted permission to read, copy and alter data, according to Berulis’ disclosure.
For cybersecurity professionals, a failure to log activity is a cardinal sin and contradicts best practices as recommended by the National Institute of Standards and Technology and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, as well as the FBI and the National Security Agency.
Those forensic digital records are important for record-keeping requirements and they allow for troubleshooting, but they also allow experts to investigate potential breaches, sometimes even tracing the attacker’s path back to the vulnerability that let them inside a network. The records can also help experts see what data might have been removed. Basic logs would likely not be enough to demonstrate the extent of a bad actor’s activities, but it would be a start. There are no reasons for a legitimate user to turn off logging and other security tools.
“If he didn’t know the backstory, any [chief information security officer] worth his salt would look at network activity like this and assume it’s a nation-state attack from China or Russia,” said Braun, the former White House cyber official.
Massachusetts Institute of Technology graduate and DOGE engineer Jordan Wick had been sharing information about coding projects he was working on to his public account with GitHub, a website that allows developers to create, store and collaborate on code.
Several experts who review Berulis’ work, say the name suggests thatWick could have created a back door to extract files from the NxGen case management system.
The NxGen case management system of the NLRB: What did the engineer behind it install? How did the DOGE engineer tell Berulis?
“So when I saw this tool, I immediately panicked, just for lack of a better term,” he said. “I kind of had a conniption and said, ‘Whoa, whoa, whoa.'” He immediately alerted his whole team.
One of the engineers who built NxGen, and asked for anonymity so that they could not jeopardize their ability to work with the government again, said it was odd to call it that. If you’re not worried about consequences, you’re brazen.
The engineers explained that while many of the NLRB’s records are eventually made public, the NxGen case management system hosts proprietary data from corporate competitors, personal information about union members or employees voting to join a union, and witness testimony in ongoing cases. Access to that data is protected by numerous federal laws, including the Privacy Act.
“None of that confidential and deliberative information should ever leave the agency,” said Richard Griffin, who was the NLRB general counsel from 2013 to 2017, in an interview with NPR.
He counted on the remnants of DOGE leaving some clues and puzzle pieces that he could assemble to try and figure out what happened.
Then, DOGE engineers installed what’s called a “container,” a kind of opaque virtual computer that can run programs on a machine without revealing its activities to the rest of the network. On its own, that wouldn’t be suspicious, though it did allow the engineers to work invisibly and left no trace of its activities once it was removed.
While investigating the data taken from the agency, Berulis tried to determine its ultimate destination. But whoever had exfiltrated it had disguised its destination too, according to the disclosure.
DOGE took what it was looking for, but no one else had access to the NLRB’s database, or did it take more data? A whistleblower disclosure details how DOGE may have taken sensitive labor data
From what he could see, the data leaving, almost all text files, added up to around 10 gigabytes — or the equivalent of a full stack of encyclopedias if someone printed them, he explained. The agency itself hosts over 10 terabytes of historical data, but it is a large chunk of the total data. It’s unclear which files were copied and removed or whether they were consolidated and compressed, which could mean even more data was exfiltrated. The disclosure points out that it’s possible that DOGE looked for specific files in the NLRB’s system and only took what it was looking for.
Regardless, that kind of spike is extremely unusual, Berulis explained, because data almost never directly leaves from the NLRB’s databases. There’s only one noticeable spike of data exiting the system that Berulis shared in his disclosure. He also confirmed that no one at the NLRB had been saving backup files that week or migrating data for any projects.
When an external party like the inspector general is granted guest accounts on the system, they are only allowed to view files relevant to their case or investigation, according to labor law experts who worked with the National Labor Relations Board.
The disclosure said they prepared a request for assistance from the cybersecurity and infrastructure security agency. Efforts were disrupted without an explanation. That was deeply troubling to Berulis, who felt he needed help to try to get to the bottom of what happened and determine what new vulnerabilities might be exploited as a result.
“This case has been particularly sensitive as it involves the possibility of sophisticated foreign intelligence gaining access to sensitive government systems, which is why we went to the Senate Intelligence Committee directly.”
Berulis was able to find some troubling details about what happened while DOGE was being used, which he enumerated in his official declaration.
Source: A whistleblower’s disclosure details how DOGE may have taken sensitive labor data
Berulis’s disclosure of his encounters with the DOGE hacker, via DNS tunneling, revealed by an employer’s whistleblower
A SAS token, which is called a high-level access key, is given to users to access storage accounts. Berulis said there was no way to track what they did with it.
Five downloads of a task automation program was what Berulis said he noticed on the system. There were several code libraries that got his attention — tools that he said appeared to be designed to automate and mask data exfiltration. There was an automation tool for web developers called “browserless,” and a tool to generate a seemingly endless number of IP addresses called “requests-ip-rotator.” Both of these were favorites by the DOGE engineer, according to an archive of his GitHub.
Berulis says someone appeared to be doing something called DNS tunneling to prevent the data exfiltration from being detected. He came to that conclusion, outlined in his disclosure, after he saw a traffic spike in DNS requests parallel to the data being exfiltrated, a spike 1,000 times the normal number of requests.
When someone uses this technique, they set up a domain name that will ping the system with questions or queries. But they configure the compromised server so that it answers those DNS queries by sending out packets of data, allowing the attacker to steal information that has been broken down into smaller chunks.
Source: A whistleblower’s disclosure details how DOGE may have taken sensitive labor data
What DOGE can do about the case management system? A comment on Berulis’s “Understanding the sensitivity of the NLB system”
The researcher said that they were given the keys to the front door. While the researcher said it would be impossible to fully verify what happened without full access to the NLB system, they said Berulis’ conclusions and evidence were cause for concern. “None of this is standard,” they said.
Russ Handorf reviewed Berulis’ technical forensic records and analysis and spoke to NPR about his conclusions.
“All of this is alarming,” he said. I would have to report it to the SEC if this was a publicly traded company. The timeline of events demonstrates a lack of respect for the institution and for the sensitivity of the data that was exfiltrated. There is no reason to increase the security risk profile by disabling security controls and exposing them, less guarded, to the internet. They did not copy data to local media for escort as required by the standard practice.
It houses information about ongoing contested labor cases, lists of union activists, internal case notes, personal information from Social Security numbers to home addresses, proprietary corporate data and more information that never gets published openly.
There are inefficiencies that need to be reviewed but experts say there is no reason to remove the data from the case management system.
There is no reason to look at the information. Was any agency more efficient? More effective? Positively. You need people who understand what the agency does. Harley Shaiken, a professor emeritus at the University of California, Berkeley who specializes in labor and information technology, said that this is not happening because of mining data or putting Algorithms in.
“I don’t see how doge follows any standard procedures for doing an audit that has integrity, which is important and will produce results that serve the auditing function of looking for fraud, waste, and abuse,” he said.
The mismatch between what they are doing and the established, professional way of doing it is giving away the store, that they are not actually searching for more efficient ways for the government to operate.
Source: A whistleblower’s disclosure details how DOGE may have taken sensitive labor data
The implications of the National Labor Relations Board’s investigation into information leaks from SpaceX employees and other union-organizing employees – a working-class worker empowerment network
The potential for sensitive records to be copied is a serious danger that could cause great harm to employees who seek protection from the National Labor Relations Board.
“If they have access to the data, then it’s not really intimidating” said Kate Bronfenbrenner, who is also the co-director of the Worker Empowerment Research Network. “You know, people are going to say, ‘I don’t want to testify because my employer might get access’.”
Bronfenbrenner, the child of immigrant parents who fled the Soviet Union and Nazi-controlled Germany, said she spends a lot of time thinking about how systems can crumble under the right circumstances. “Any person who is in the labor movement should know that we do not have these checks and balances,” she said.
With access to the data, it would make it easier for companies to fire employees for union organizing or keep blacklists of organizers — illegal activities under federal labor laws enforced by the NLRB. But “people get fired in this country all the time for the lawful act of trying to organize a union,” said Block.
It’s not just employees who might suffer if this data got out. In the wake of unfair-labor-practice complaint proceedings, companies can make detailed statements on their internal business planning and corporate structure. If a company was attempting to fire someone who it alleged had disclosed trade secrets and was fighting an unfair-labor-practice complaint based around that decision, those trade secrets might come up in the board’s investigation too. That information would be valuable to competitors, regulators and others.
“I think the situation is very concerning,” said Shaiken. “It could result in damage to individual workers, to union-organizing campaigns and to unions themselves,” he said.
There are numerous ongoing cases of the NLRB with Musk’s companies. After a group of former SpaceX employees lodged a complaint with the NLRB, lawyers representing SpaceX, some of whom were recently hired into government jobs, filed suit against the NLRB. They claimed that the agency’s structure is unconstitutional.
During an interview with Sean Hannity, Trump and Musk said Musk wouldn’t be involved in anything connected to his companies. Musk said that he had never asked the president for anything. I am getting a daily proctology exam here. It’s not like I will be able to get away with something in the dead of night. However, DOGE has been granted high-level access to a lot of data that could benefit Musk, and there has been no evidence of a firewall preventing misuse of that data.
Chris Murphy raised his concerns about Musk accessing labor investigation data on cases against his companies during the confirmation hearing for Trump’s labor secretary. He pressed her to say if she believed the NLRB is constitutional, and also if she wanted to keep sensitive data confidential. She insisted that Trump “has the executive power to exercise it as he sees fit,” despite her claims that she was committed to privacy.
The creation of the NLRB was to make sure that workers have the right to organize in the workplace. Under President Joe Biden, he recalled, the labor movement enjoyed an unusual amount of support from Washington. He said that they have seen a sharp slamming of the brakes and putting the vehicle in reverse so that they could see what Trump had done.
In addition to sending DOGE to the NLRB, the Trump administration tried to neutralize the board’s power to enforce labor law by removing its member Gwynne Wilcox. Courts have gone back and forth on whether Wilcox’s removal was illegal, as presidents are meant to demonstrate cause for dismissal of independent board members.
The Harvard Law’s Block: How Do NLRB Administrators and FBI Cyber Officials can be on the Lookout for Spyware Attacks?
Harvard Law’s Block says that he’s not a random person that shouldn’t have access to that information. “But if they really did get everything, then he has information about the cases the government is building against him,” she said.
“DOGE is, whether they admit it or not, headed by somebody who is the subject of active investigation and prosecution of cases. It is incredibly troubling,” she said.
Musk’s company xAI could also benefit from sucking up all the data DOGE has collected to train its algorithms. Cybersecurity experts like Bruce Schneier, a well-known cryptographer and adjunct lecturer at the Harvard Kennedy School, have pointed to this concern at length in interviews and written pieces.
According to two federal government sources who were not authorized to speak publicly about their workplaces and who shared email documentation with NPR, managers have consistently been warning employees that their data could be subject to AI review, particularly their email responses to the Musk-led campaign to get federal employees to detail “what they did last week” in five bullet points every Monday.
“It’s not a flight of imagination to see several DOGE staffers release some of that [data] surreptitiously to Musk or people close to him,” said Shaiken.
“Both criminals and foreign adversaries traditionally have used information like this to enrich themselves through a variety of actions,” explained Handorf, the former FBI cyber official. “Anything that involves blackmail, targeting and prioritization of intellectual property theft for espionage or even harming a company to enrich another” is included.
In fact, in the minutes after DOGE accessed the NLRB’s systems, someone with an IP address in Russia started trying to log in, according to Berulis’ disclosure. Those attempts were blocked, but they were especially alarming. The person who was trying to log in was using a new account created by DOGE, according to Berulis.
Handorf stated that the opportunity to ride the coattails of authorized access was easy to achieve. It would be easy for spies to break in and steal information from the DOGE network if access points were left open.
“This is exactly why we usually architect systems using best practices like the principle of least privilege,” Ann Lewis, the former director of Technology Transformation Services at the General Services Administration, told NPR in an interview. “The principle of least privilege is a fundamental cybersecurity concept … that states that users should have only the minimum rights, roles and permissions required to perform their roles and responsibilities. This protects access to high-value data and critical assets and helps prevent unauthorized access, accidental damage from user errors and malicious actions. “
A judge blocked DOGE access because she believed that sensitive data had already been shared outside of the Treasury Department.
The Cybersecurity and Infrastructure Security Agency in the Interior Department was forced to relocate or put on administrative leave because of the cybersecurity officials’ resignation or being fired. They can’t always respond to the ongoing disruptions or keep track of DOGE’s activities.
One of the first people to speak out about DOGE’s access to sensitive data was Erie Meyer, who resigned as the chief technology officer at the Consumer Financial Protection Bureau (CFPB) in February. She has provided testimony in ongoing court cases surrounding DOGE’s access and also spoke to NPR in an interview. The data of the CFPB could have an impact on the market. Meyer said DOGE employees granted themselves “God-tier” access to the CFPB’s systems, turned off auditing and event logs and put the cybersecurity experts responsible for insider threat detection on administrative leave. She stated that when the IT experts of the bureau planned to do a report on DOGE’s activities, they were stonewalled.
She was able to see a pattern when she heard that the engineers at the NLRB took steps to hide their activities.
“I am trembling,” she said upon hearing about the potential exposure of data from the NLRB. “They can get every piece of whistleblower testimony, every report, everything. This is not good.”
“Our cyber teams are pissed because they have to sit on their hands when every single alarm system we have regarding insider threats is going off,” said one employee at an agency of the Interior Department who requested anonymity, fearing retribution. The employee was told to stand down while he was trying to shut off new users’ access to the system.
Meanwhile, in a letter published on March 13 on Federal News Network, 46 former senior officials from the General Services Administration, one of the government agencies hardest hit by DOGE’s cost-cutting efforts and that oversees nearly all federal buildings and purchasing, wrote that they believed “highly-sensitive IT systems are being put at risk and sensitive information is being downloaded to unknown, unvetted external sources in clear violation of privacy and data-protection rules.”
The Trump administration could be trying to codify DOGE’s practices into how the government shares information, said Kel McClanahan, the executive director of nonprofit public interest law firm National Security Counselors, who is representing federal employees in a lawsuit concerning the Office of Personnel Management’s use of a private email server.
“The entire reason we have a Privacy Act is that Congress realized 50 years ago that the federal government was just overflowing with information about normal everyday people and needed some guardrails in place,” McClanahan told NPR. The information silos are there because of that. It’s astounding to me that the people who used to be screaming about the government tracking us with vaccines now cheer for the information they’ve been given into Musk’s Skynet.
“This shocks the conscience,” said Richard Griffin, the former general counsel of the NLRB. If DOGE operatives captured and removed case files it could constitute a violation of the Privacy Act.
For Berulis, it was important to speak out, because he believes people deserve to know how the government’s data and computer systems are at risk, and to prevent further damage. Berulis said he would have been fired if he operated like DOGE.
He believes that the project goes far beyond just case data. I know some people who have seen similar behavior at other agencies. I firmly believe that it is happening at other agencies as well.
He stated that his goal was to give Congress information that they don’t necessarily know about, such as things that they don’t look for.
What do DOGE engineers think about the electronic access control system? The DOGE memo to Berulis, C.S.C., A.R.D., Jan. 22, 2002
Berulis had a simple request for the DOGE engineers: “Be transparent. If you have nothing to hide, don’t delete logs, don’t be covert. … Be open, because that’s what efficiency is really about. If this is a huge misunderstanding, just prove it. Put it out in the open. That’s all I’m asking.”
“This could just be the start of the operation. … They still haven’t crossed that boundary where they’re plugged into every federal system out there,” he continued. Maybe there is more time left.
According to the disclosure, someone had disabled controls that would prevent insecure or unauthorized mobile devices from logging on to the system without the proper security settings. There was an interface exposed to the public internet, potentially allowing malicious actors access to their systems. Internal alerting and monitoring systems were found to be manually turned off. Multifactor was not working.
Having a list of key organizers and potential members of a union would make that easier, as would having a copy of the opposing counsel’s notes as companies prepare for legal challenges, she continued.



