NLRB denies breach
Berulis’ disclosure said that several days before receiving this threat, he had been instructed to drop his investigation and not report his concerns to US security officials.
Bakaj’s letter to senators and the Office of Special Counsel requested “that both law enforcement agencies and Congress initiate an immediate investigation into the cybersecurity breach and data exfiltration at NLRB and any other agencies where DOGE has accessed internal systems.”
An NLRB spokesperson denied that there was any breach. “Tim Bearese, the NLRB’s acting press secretary, denied that the agency granted DOGE access to its systems and said DOGE had not requested access to the agency’s systems,” according to NPR. “Bearese said the agency conducted an investigation after Berulis raised his concerns but ‘determined that no breach of agency systems occurred.'”
The email said the NLRB “had no official contact with any DOGE personnel” prior to this week, but met with DOGE representatives on Wednesday morning.
There have been numerous lawsuits over the access to government systems granted to DOGE, the Trump administration entity led by Elon Musk. One such lawsuit described DOGE’s access as “the largest and most consequential data breach in US history.” There have been mixed results in the cases so far; a US appeals court decided last week that DOGE can access personal data held by the US Department of Education and Office of Personnel Management (OPM), overturning a lower-court ruling.
After the whistleblower disclosure, US Rep. Gerry Connolly (D-Va.) sent a
Because of Musk’s role at DOGE and the fact that his “companies face a series of enforcement actions from NLRB and DOL,” there is “an inherent conflict of interest for him to direct any work at either agency—let alone benefit from stolen nonpublic information,” Connolly wrote.
Login attempts from Russia
Berulis’ disclosure said that on March 11, internal metrics indicated there had been “abnormal usage” over the past week with higher-than-usual response times and “increased network output above anywhere it had been historically.” When examining the data, “we noticed a user with an IP address in Primorsky Krai, Russia started trying to log in. Those attempts were blocked, but they were especially alarming,” he wrote.


