Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

erronis

(19,464 posts)
Thu Mar 20, 2025, 08:24 AM Mar 20

DOGE to Fired CISA Staff: Email Us Your Personal Data -- Krebs On Security

https://krebsonsecurity.com/2025/03/doge-to-fired-cisa-staff-email-us-your-personal-data/

All DOGE-accessible data has already made its way to russia and possibly china by now.

A message posted on Monday to the homepage of the U.S. Cybersecurity & Infrastructure Security Agency (CISA) is the latest exhibit in the Trump administration’s continued disregard for basic cybersecurity protections. The message instructed recently-fired CISA employees to get in touch so they can be rehired and then immediately placed on leave, asking employees to send their Social Security number or date of birth in a password-protected email attachment — presumably with the password needed to view the file included in the body of the email.

The homepage of cisa.gov as it appeared on Monday and Tuesday afternoon.

On March 13, a Maryland district court judge ordered the Trump administration to reinstate more than 130 probationary CISA employees who were fired last month. On Monday, the administration announced that those dismissed employees would be reinstated but placed on paid administrative leave. They are among nearly 25,000 fired federal workers who are in the process of being rehired.

A notice covering the CISA homepage said the administration is making every effort to contact those who were unlawfully fired in mid-February.


“Please provide a password protected attachment that provides your full name, your dates of employment (including date of termination), and one other identifying factor such as date of birth or social security number,” the message reads. “Please, to the extent that it is available, attach any termination notice.”

The message didn’t specify how affected CISA employees should share the password for any attached files, so the implicit expectation is that employees should just include the plaintext password in their message.

Email is about as secure as a postcard sent through the mail, because anyone who manages to intercept the missive anywhere along its path of delivery can likely read it. In security terms, that’s the equivalent of encrypting sensitive data while also attaching the secret key needed to view the information.

. . .
2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
DOGE to Fired CISA Staff: Email Us Your Personal Data -- Krebs On Security (Original Post) erronis Mar 20 OP
Top secret govt employees putting personal data in emails to DOGE hackers. Irish_Dem Mar 20 #1
THESE are the little techno-terrorists who have access to ALL of our personal data now. CousinIT Mar 20 #2

Irish_Dem

(69,288 posts)
1. Top secret govt employees putting personal data in emails to DOGE hackers.
Thu Mar 20, 2025, 08:26 AM
Mar 20

Sounds safe doesn't it.

CousinIT

(11,324 posts)
2. THESE are the little techno-terrorists who have access to ALL of our personal data now.
Thu Mar 20, 2025, 09:08 AM
Mar 20

And THIS is the level of understanding (or caring about) systems and data security they demonstrate.

I'm sure it will be fine though. RIGHT?

Latest Discussions»General Discussion»DOGE to Fired CISA Staff:...