Live data from Hacker News

Whistleblower statement on anomalies at time of DOGE work at NLRB [pdf]

whistlebloweraid.org

1–10 of 20 posts

Re: Whistleblower statement on anomalies at time of DOGE work at NLRB [pdf]

#4
> This declaration details DOGE activity within NLRB, the exfiltration of data from NLRB systems, and – concerningly – near real-time access by users in Russia. Notably, within minutes of DOGE personnel creating user accounts in NLRB systems, on multiple occasions someone or something within Russia attempted to login using all of the valid credentials (eg. Usernames/Passwords). This, combined with verifiable data being systematically exfiltrated to unknown servers within the continental United States – and perhaps abroad – merits investigation.

> Furthermore, on Monday, April 7, 2025, while my client and my team were preparing this disclosure, someone physically taped a threatening note to Mr. Berulis’ home door with photographs – taken via a drone – of him walking in his neighborhood. The threatening note made clear reference to this very disclosure he was preparing for you, as the proper oversight authority. While we do not know specifically who did this, we can only speculate that it involved someone with the ability to access NLRB systems. This “meat space” action – where a threat was physically delivered to my client’s home – is absolutely disturbing in its manner and the implications suggested therein. Accordingly, and we have been and will continue to be coordinating with appropriate law enforcement agencies.

Re: Whistleblower statement on anomalies at time of DOGE work at NLRB [pdf]

#5
post #2

Any opinions from cybersecurity experts? Is this concerning or over-hyped drama?

still feels like until we get some more grounded evidence, it's speculation:

"Mr. Berulis is coming forward today because of his concern that recent activity by members of the Department of Government Efficiency (“DOGE”) have resulted in a significant cybersecurity breach that likely has and continues to expose our government to foreign intelligence and our nation’s adversaries"

operative words here being "likely has"

Re: Whistleblower statement on anomalies at time of DOGE work at NLRB [pdf]

#7
post #2

Any opinions from cybersecurity experts? Is this concerning or over-hyped drama?

Cybersecurity "expert" here. This seems to be under-hyped, if possible. If there were login attempts that even appeared to be coming from Russia using valid credentials that were created less than an hour before, it can really only be explained by collusion or an attacker having visibility into the process that created the credentials in the first place.

The fact that the traffic appeared to be coming from Russia isn't particularly compelling, as it's very easy to make your web traffic appear to be coming from another country. But I struggle to understand why a legitimate user of those credentials would willfully make their legitimate use of government systems appear to be coming from an adversary.

Re: Whistleblower statement on anomalies at time of DOGE work at NLRB [pdf]

#8
post #2

Any opinions from cybersecurity experts? Is this concerning or over-hyped drama?

Obviously you have to trust the guy, but if you do this part is already extremely damning.

>received a call during which an ACIO stated instructions were given that we were not to adhere to SOP with the doge account creation in regards to creating records. He specifically was told that there were to be no logs or records made of the accounts created for DOGE employees. DOGE officials required the highest level of access and unrestricted access to internal systems. They were to be given what are referred to as “tenant owner” level accounts

If you seek the opinion of a "security expert" I'd recommend reading the sworn affidavit in Exhibit A. He seems competent, and perjury there seems less likely than here on HN. It's quite well formulated.

Re: Whistleblower statement on anomalies at time of DOGE work at NLRB [pdf]

#9
post #2

Any opinions from cybersecurity experts? Is this concerning or over-hyped drama?

From a cursory read, it says "DOGE came in, were given super-admin access without following procedures, and without a written track, and then plenty of logging was disabled and strange stuff started appearing".

If you ask me, it's the equivalent of the FBI inviting themselves into your home, telling you to "not come back until tomorrow" and then bugging it cellar to roof.

Post reply on HN