Ignoring the horrifying political parts, I think one aspect here about data access that is inherently worrying is that it seems like all usual controls were bypassed and the DOGE people had very low level access to systems. So there are probably copies of sensitive data now in their possession, and nobody knows exactly what was copied and where it is stored. This kind of access would be dangerous even in the hands of…
What's more worrying is whether the access can realistically be revoked. As a general rule, when a security even rises to the level of root access to internal systems, you don't even try to remove them - you just rebuild the affected VMs from scratch because it's the only way to be sure the attacker didn't leave anything behind. For the systems we're talking about, payment processing stuff at Treasury and Social Secu…
These people have administrative access, and at least in some cases network and physical access.
Once you determine they are untrustworthy and potentially malicious, you can't just rebuild the VMs, since you can no longer trust the hypervisor or even the hardware.
If they were Chinese or Mossad agents, you'd start from scratch in a different DC on supply chain audited new compute, storage, and networking hardware. And you'd compile everything from audited source. And I have NFI how you'd deal with potential malicious changes to your data and backups.