DOGE API Key Leak: xAI’s Marko Elez Involved – Krebs on Security
DOGE Staffer’s Security Lapses Expose Sensitive Government Data, Raising Alarms
Table of Contents
A pattern of operational security failures by a Department of Defense (DoD) contractor working on a sensitive government project has led to the exposure of unencrypted personal data and internal API keys, raising serious concerns about the security of government systems and the vetting of personnel.
Unencrypted Data Leak Sparks Investigation
in March 2025, a staffer working on the Department of Defense’s (DoD) “Data Operations Group Enterprise” (DOGE) initiative, identified as Marko Elez, was found to have violated Treasury rules. The violation involved emailing unencrypted personal data, a breach that triggered an investigation into the handling of sensitive data. This incident,first reported by KrebsOnSecurity,highlighted a critical lapse in basic cybersecurity practices.
Elez’s Extensive Government Ties Revealed
Further reporting has uncovered Elez’s extensive involvement across various government agencies, raising questions about the oversight and security protocols in place for individuals with access to sensitive national data.
Social Security Governance: In February 2025, elez was reported to be working at the Social Security administration. Department of Labor: Business Insider revealed in March 2025 that Elez was part of a DOGE detachment assigned to the Department of Labor.
Homeland Security Agencies: The New York Times reported in April 2025 that elez held positions within U.S. Customs and Border Protection and Immigration and Customs Enforcement (ICE), as well as the Department of Homeland Security.
Department of Justice: the Washington Post later reported that while serving as a DOGE advisor at the Department of Justice, Elez gained access to the Executive Office for Immigration Review’s Courts and Appeals System (EACS).
Marko Elez, in a photo from a social media profile.
Pattern of Security Breaches Extends to API Keys
The unencrypted data leak is not an isolated incident. Elez is not the first DOGE worker to expose sensitive information. In May, KrebsOnSecurity detailed how another DOGE employee leaked a private xAI API key on GitHub for two months. This exposed Large Language Models (LLMs) that were custom-built for handling internal data from Elon Musk’s companies, including SpaceX, Tesla, and Twitter/X.
Expert Concerns Over Negligence and Security Culture
Security experts are voicing important concerns about the implications of these repeated breaches. Caturegli, a cybersecurity analyst, commented on the gravity of the situation, stating, “It’s challenging to trust someone with access to confidential government systems when they can’t even manage the basics of operational security.”
He further elaborated on the systemic issues at play: “one leak is a mistake. But when the same type of sensitive key gets exposed again and again, it’s not just bad luck, it’s a sign of deeper negligence and a broken security culture.”
These incidents underscore the urgent need for enhanced vetting, robust security training, and a stronger security culture within government contracting and sensitive data handling environments. The potential for widespread compromise of personal and national security data remains a significant threat as long as such operational security lapses persist.
