Drooid Logo
Back to story perspectives

Full Breakdown

GAO Report Highlights Security Gaps in Treasury Payment Systems Linked to DOGE Access

4/30/2026, 3:43:46 AM

Core Findings: Unrestricted DOGE Access to BFS Payment Systems

The Government Accountability Office’s April 28 audit found that a Department of Government Efficiency (DOGE) employee—identified by GAO as Marko Ele­z—was granted the ability to view, copy and print data from the Treasury’s three Bureau of the Fiscal Service (BFS) payment systems, which process tax refunds, benefits, salaries and other federal disbursements. Ele­z was also “inadvertently” given temporary permission to create, modify and delete data in one system, though GAO uncovered no evidence of actual changes. The employee had not completed required security training nor signed Treasury’s IT-security “rules of behavior.”

Background: DOGE’s Creation and Role in Treasury

President Donald Trump established DOGE on the first day of his second administration to cut federal workforce size, reduce spending and modernize government technology. Elon Musk initially led the collective, stepped away in May 2025, and most DOGE functions were later transferred to the Office of Personnel Management. DOGE’s Treasury detail began in January 2025 with two temporary staff members tasked with projects involving BFS payment systems.

Key Figures and Entities

  • Marko Ele­z – DOGE staffer with privileged BFS access.
  • Rep. Richard Neal (D-Mass.) – Top Democrat on the Ways and Means Committee, vocal about GAO findings.
  • Sen. Gary Peters (D-Mich.) – Critic of DOGE’s data-handling practices.
  • Timothy E. Gribben – BFS Commissioner, responded to GAO recommendations.
  • Whistleblower Aid – Legal counsel for an NLRB whistleblower.
  • GAO – Issuer of the audit and its six recommendations.

Data and Security Lapses

  • Unencrypted transmission of personally identifiable information for 350 individuals listed for USAID payments to two DOGE associates at the General Services Administration.
  • BFS had implemented only 5 of 14 selected cybersecurity controls for overseeing users with broad payment-system access.
  • The department’s data-loss-prevention tools failed to detect or block the unencrypted file transfer.
  • No exit interview or post-employment documentation was obtained from the DOGE employee before departure, leaving an interim security clearance active.

Official Statements & Responses

Rep. Neal said GAO “has confirmed our worst fears” and urged Treasury to adopt all GAO recommendations. BFS Commissioner Gribben replied that the bureau “has undertaken significant efforts to implement cybersecurity controls … and is continually working to improve its implementation and monitoring.” Treasury formally agreed with three of GAO’s six recommendations while declining to comment on the remaining three.

Criticism & Opposition

Sen. Peters warned that DOGE officials “risk Americans’ personal data by uploading sensitive information to the cloud without proper safeguards.” Rep. Neal called for full implementation of GAO’s recommendations, emphasizing the potential for misuse of payment data. Whistleblower Aid argued that GAO’s investigative timeframe (January–February 2025) excluded the period (February–April 2025) during which its client observed alleged wrongdoing.

Conflicting Reports & Gaps

GAO’s scope omitted the whistleblower’s alleged misconduct window, creating a gap between the audit and the whistleblower’s claims. A district-court preliminary injunction initially limited DOGE’s Treasury access, but the order was later modified to permit limited access, leaving the exact extent of permissible activity unclear. While GAO found no evidence of data alteration, separate whistleblower allegations suggest extensive data extraction at the NLRB, which remains under investigation.

Verbatim Quotes

  • “GAO has confirmed our worst fears,” — Rep. Richard Neal, D-Mass.
  • “BFS has undertaken significant efforts to implement cybersecurity controls over its payment systems, and it is continually working to improve its implementation and monitoring of cybersecurity controls,” — Timothy E. Gribben, BFS Commissioner
  • “Because the GAO did not investigate any matters that fell within the timeframe disclosed by our client — in fact scoping it out of their investigation — the report cannot address our client's detailed accounts,” — Whistleblower Aid
  • “Until Treasury and BFS fully establish and implement controls for overseeing users with broad access to payment systems, this important information will be at a greater risk of improper access, modification, disclosure, or misuse,” — GAO, audit conclusion
  • “According to BFS officials, employee B did not obtain approval from the bureau to send this information outside the agency,” — GAO, audit finding

What’s Next: Ongoing Oversight and Litigation

GAO announced plans for additional audits of DOGE access to Treasury systems. The district court’s modified injunction and the NLRB Inspector General’s investigation remain active, while Treasury considers whether to adopt the remaining GAO recommendations concerning exit interviews and post-employment documentation.