Post
🧵 THREAD: A federal whistleblower just dropped one of the most disturbing cybersecurity disclosures I’ve ever read.
He's saying DOGE came in, data went out, and Russians started attempting logins with new valid DOGE passwords
Media's coverage wasn't detailed enough so I dug into his testimony:
April 18, 2025 at 9:10 AM
4.5K reposts
654 quotes
8.4K likes
Who’s the whistleblower?
Daniel Berulis — a senior DevSecOps architect at the National Labor Relations Board (NLRB), formerly with TS/SCI clearance.
He just told Congress the Department of Government Efficiency (DOGE) pulled off a covert cyber op inside a federal agency.
DOGE demanded root access.
Not auditor access. Not admin.
They were given “tenant owner” privileges in Azure — full control over the NLRB’s cloud, above the CIO himself.
This is never supposed to happen.
They disabled the logs.
Berulis says DOGE demanded account creation with no recordkeeping.
They even ordered security controls bypassed and disabled tools like network watcher so their actions wouldn’t be logged.
And then the data started flowing out.
10+ GB spike in outbound traffic
Exfiltration from NxGen, the NLRB's legal case database
No corresponding inbound traffic
Unusual ephemeral containers and expired storage tokens
They used an external library that used AWS IP pools to rotate IPs for scraping and brute force attacks.
They downloaded external GitHub tools like requests-ip-rotator and browserless — neither of which the agency uses.
The most daming claim in this statement IMO:
Within 15 minutes of DOGE accounts being created…
Attackers in Russia tried logging in using those new creds.
Correct usernames and passwords.
2 options here. The DOGE device was hacked. And I don't think I need to explain the 2nd.
Multi-factor authentication? Disabled.
Someone downgraded Azure conditional access rules — MFA was off for mobile.
This was not approved and not logged.
Cost spikes without new resources.
Azure billing jumped 8% — likely from short-lived high-cost compute used for data extraction, then deleted.
Then came the intimidation.
While preparing this disclosure, Berulis found a drone surveillance photo of himself taped to his front door with a threatening note.
This was just a few days ago.
Continue thread...
Maddow covered the story for the masses. Great interview. Guy is clearly shaken. At times, his lawyer spoke for him because of it. m.youtube.com/watch?v=DLPL...
the original story / scoop / feature story by npr cybersecurity reporter had all these relevant details & much more. don’t understand how you could have missed that? she’s great & her work on this has been extremely valuable.
American Radio: our listeners asked us: “Why Trump's DOGE always operate in teams of 3?”
Answer: “The partners in DOGE teams are always chosen in such a way that one of them knows how to read, the other how to write, and the third one, naturally, has to keep watch over those two intellectuals.”
Ça y est ils commencent à se rendre compte que le gus est placé là par Vladimir. Il aura fallu du temps :)
Versteh ich das richtig, diese Behörde sabotiert alles möglich, dass sie für Russland leichter zu hacken sind.
Zum Kontext:
"Das National Labor Relations Board ist eine unabhängige Bundesbehörde der Vereinigten Staaten, die für die Überwachung und Durchsetzung der Arbeitsbeziehungen zwischen Arbeitgebern und Arbeitnehmern zuständig ist. Das NLRB wurde 1935 gegründet"
.../2
Und
a) Doge (E Musk boys) hat "alle"/SEHR viele Daten extrahiert
b) gleiche Zugänge sind innert 15' von Computer in Russland benützt worden
"The NLRB has had no official contact with any DOGE personnel. We have not granted DOGE access to any agency systems, nor has DOGE requested access to agency system… At this point in time, we have no evidence of any unauthorized or unusual activity on agency systems,”
www.forbes.com/sites/johnhy...
William Cowen, the NLRB counsel who made that statement?
Oh, yeah, not sus at all
Until there's an investigation with concrete findings, it’s all still in the realm of unproven accusations.
You're right. DOGE has been transparent with all their actions so we will soon know the truth.
Good job.
I don’t think non-IT folks appreciate how many of these things DOGE did are *never* allowed- the logs disabled, the root access, the MFA turned off, etc.
All part of “defense in depth” to prevent data tampering or theft.
DOGE systematically dismantled all security controls & audits.
Among all the other costs, any sane future administration will have to replace all this cyber infrastructure because you have to assume it’s all completely compromised now
Since we can’t get the DOJ to do anything about this, shouldn’t the organizations and people whose data was put at risk sue?
Yes, the unions should sue DOGE 🥴 it will go like miracle on 34th street
Not detailed enough? My story breaking the news was 7k words!
And with no paywall!
www.npr.org/2025/04/15/n...
We need more reporting connecting all the “Trump as Russian asset” dots! This is a huge piece of the puzzle.
I’ve been saying since DOGE started it was all about information and access. I was t even thinking about the Russians getting access. Things are getting far worse (in some respects) than I had anticipated.
Please share and help if you can, we need a hand.
gofund.me/e1c99db8
Seems like a certain billionaire should be arrested.
from the beginning, this was always a hostile, government-wide hack of our systems, with intent. considering who’s in charge, not even a little surprising its all in Russia’s hands. this was planned and ordered by hostiles. wait until weird seemingly random shit starts breaking. grids, banking etc
You could've said where you got this from www.npr.org/2025/04/15/n...
I didn't get it from here. Apologies and I've added this to the thread.
The problem here is that this letter is addressed to James Comer....
You could have at least credited the reporter doing heavy lifting on this over at NPR.
need to arrest all these traitors... doge was not about saving money, it was a russian attack
As I said in my post yesterday: implication is doge are directly working for the Russians or are so thoroughly penetrated by Russia, any info given to them is given to Russia
Remember this? I can't believe nobody gave a single shit and now here we are.
I gave a shit. The media is hiding this.
The DOGE boys are running around all of USG carrying phones, laptops, and god knows what other unapproved devices, all of which have likely been thoroughly pwned by a dozen foreign intelligence services. I suppose it's "government efficiency" for Russia, not so much for us.
NPR covered this story two nights ago, nearly as in-depth as you present here, though you specifically list the tools used, etc. I was livid and sick to my stomach all at the same time by the end of the story. These crimes can't continue. They must be stopped.
There are SO MANY security violations in this case, it makes my head spin. The DOGE boys need to be prosecuted for treason.
This is all treasonous. Everything is treason. Musk needs to be indicted.
@NPR broke this story earlier this week & has excellent coverage. Pls give credit where it’s due.
That makes Musk the terrorist leader! We should act accordingly.
Genuinely fucking crazy how much actual, in-the-open treason has been going on for like a decade now. And the traitors are supposedly the patriots!
This is one of the biggest stories EVER
Don’t forget, Hegseth defunded CyberCom to help facilitate the Russians avoiding detection by IP address
CyberCom Caught Them
Hegseth is Firing Them
Traitors all around us NOW
It’s up to government workers to whistle blow or stop the attack
TheRealZMAN
🔥🍋
And they are attempting to install that DC Attorney who went on RT over 50 times. He would have jurisdiction over any cyber intelligence cases.
For everyone saying it’s an essential read, you can do that right here
bsky.app/profile/jenn...
My story breaking this news exclusively was 7K+ words and had almost all of this in it, and more:
www.npr.org/2025/04/15/n...
I'm gonna use some of this in my performance review. Examples of shit I'm not doing in my IT Job.
If Bill Cassidy was made aware of this, and did nothing, just like he didn't vote down RFK Jr, knowing that RFK Jr was a disastrous choice, Cassidy had given up and given in to MAGA.
There was an in-depth, researched, detailed, extremely thorough story on this *two days ago* on NPR.
www.npr.org/2025/04/15/n...
NPR covered this fairly thoroughly 2 days ago. Where you been?
I’m sure they’ve done the same thing at every agency they’ve been too. This is just the first time we have a whistleblower report.
I wouldn't be surprised if we get a nuclear sunrise if Putin loses his war with Ukraine, courtesy of our own silos.
Seriously, the Trump Regime is bad enough that apocalypse is an plausible outcome. I REALLY hope that Europe and other major blocs decide to sabotage our abilities in this theatre.
Well that's.... f*cking horrifying. I don't even know what to say, and I work in IT including security.
This is what I thought was going on all along. The whole thing was too fast, and they hid it. If you're truly cutting 'waste', you'll be public about it.
Time to get DOGE out of the govenment and investigate them all.
I put together a summary of what was known a couple days ago, via NPR reporter Jenna McLaughlin:
www.someweekendreading.blog/bad-doggies/
And this probably happened everywhere DOGE has been.
They’re acquiring data and systems control to bring our country down. They’re traitors.
My story breaking this news exclusively was 7K+ words and had almost all of this in it, and more:
www.npr.org/2025/04/15/n...
Agents Elmo and Kraznov are laying America wide open for an all out cyber attack.
Or more. I suspect a massive attack on the energy grid or Alaska.
The Rachel Maddow Show, 4/15 Tuesday, went into huge detail about this FUBAR going on by these Muskrats (doge), and had the whistleblower on camera for a live interview, SCARED the SHIT out of me! The evidence he provided, and the evil people who are now Threatening His Life! Great info! See it!
This is because DOGE was using Starlink. The Russians have hacked int Starlink during the Ukraine war, and Starlink is therefore not secure. So the Doge passwords got hacked. Like everything else, the need to make profits leads to taking shortcuts
Elon opened the doors for Russia. On direction from Trump.
Possible but it is much more likely that Starlink has become insecure.
There is no forethought in the Musk crew - it is grab whatever you can as quickly as you can. Two links for you
1. bsky.app/profile/altn...
Every day, it just gets worse. Now Elon’s staff is moving to hide their actions — by secretly using Starlink.
We apologize for the length of this post, but we felt it was important to share the full details with you.
Trump is putting on a magnificent distraction show, isn’t he.
Where is Congress???
Oh silly me … they are hiding under their desks hoping for another distraction like the dropping stock market or bond market rising…
Is nobody concerned and seeing the connections here?
OMG. This testimony is horrific. DOGE might as well be called PUTIN.
MS should be forced to pull the Azure logs from their side and testify in front of congress too.
This is pretty wild. What does your gut say in terms of this all being legit? I can't get past the photo on the front door part - it's not logical.
We apologize for the length of this post, but we felt it was important to share the full details with you.
Our elected officials need to be more like this guy: “A threatening note was taped to his door, revealing private information and overhead drone photos of him walking his dog. The message was clear: stay silent. He didn’t. He went public.” quote from @altpark post
www.facebook.com/share/p/18pj...
You missed Maddow. She talked about this. He said there are others that can verify the info too. He has already been threatened.
Watch yesterday’s Rachel Maddow show - YouTube. The whistleblower was on with his attorney. The threat he received was scary.
As an IT person, I have been sounding this type of alarm for months. I even had a post removed from a tech message board because it was "too political" to ask if anyone else was bothered by the lack of CS in what DOGE was doing.
Fucking horrifying.
High treason. Nothing less than high treason.
There’s actually no proof it was DOGE that came in, it could very well have been russian security operatives taking advantage of the Trump-sown chaos.
And they are very likely to be doing it at other agencies.
bsky.app/profile/abso...
No-one actually knows that they were DOGE. If you were a foreign adversary like RUSSIA, this would be the perfect time to show up at government agencies pretending to be DOGE and infiltrate their systems and steal Americans’ data.
Any doubts about Mump’s allegiance to Russia should be resolved by this smoking gun
Stop equivocating: they’re Russian puppets
I am not a lawyer. I am, however, very, very well versed in these things. 30+ years with 25 in regulated and FedRAMP.
This isn't just incompetence, it isn't malfeasance, it isn't malicious. It is literally hand-delivering classified information to not just SDNs, but countries WE ARE AT WAR WITH.
"We're not a-"
We remain at war with North Korea.
Who is providing arms and armies to Russia in exchange for goods, money, and you guessed it, information from Russian hacking operations. Like identities used for their 'remote consultants' schemes.
That's the literal definition of treason.
Rachel Maddow did excellent interview to him/his lawyer in her last night’s show. It was great and scary. And the scariest thing is that probably this was done to ALL THE PLACES DOGE WENT. This is not one-off, this is the pattern - Treasury, IRS, all the places they went. We are all compromised.
We lost the hybrid war against russia. We should be hanging DOGE employees and trump for treason.
DOGE is compromised by Russia? Oh wow, it's the exact thing we all predicted ages ago!
This is obviously true just the way he walks us through it I have a husband in tech this is thorough and concise. Let’s hope they allow them to be arrested we should arrest them for stealing our data and each state should sign on
Agree. Backdoors are wide open to our Government computer systems. To our enemy.
Exactly this is a gross violation. We need a class action lawsuit going for all Americans at this point
Propublica reported all of this two days ago — in great detail.
Yes we need cyber guys on this. Jan 6 cyber guys I know shouldn’t ask. But we need you.
There‘s a thread of them here on bluesky
bsky.app/profile/altn...
We apologize for the length of this post, but we felt it was important to share the full details with you.
Hope I live long enough to read Putins' biography where he will proudly reveal his coup 😁
Anything that can be done now is only shutting the barn doors after the cows have left.
The thread as a shareable webpage: skywriter.blue/pages/did:pl....
Powered by
Yes. The NPR journalist who uncovered all this wrote a detailed report two days ago.
www.npr.org/2025/04/15/n...
Interview with whistleblower: www.pbs.org/newshour/sho...
The whistleblower could be lying about half his story and it would still be an awful indictment of the administration.
The DOGE accusations are horrible. Canning an investigation is horrible.
The whole thing has to be a crazy dumb lie for it not to be out of control bad.