Ignoring the horrifying political parts, I think one aspect here about data access that is inherently worrying is that it seems like all usual controls were bypassed and the DOGE people had very low level access to systems. So there are probably copies of sensitive data now in their possession, and nobody knows exactly what was copied and where it is stored. This kind of access would be dangerous even in the hands of…
What's more worrying is whether the access can realistically be revoked. As a general rule, when a security even rises to the level of root access to internal systems, you don't even try to remove them - you just rebuild the affected VMs from scratch because it's the only way to be sure the attacker didn't leave anything behind. For the systems we're talking about, payment processing stuff at Treasury and Social Secu…
What will happen when PIIs of every individual with dealings with the Treasury gets leaked?
Then there is going to be thousands of hours of meetings to review various processes...