• News/
  • https://www.theregister.com/2025/05/12/doge_cyber_experts_creds_found/

DOGE worker’s old creds found in malware data dumps

The Register
·
Brandon Vigliarolo
·
Published May 12, 2025
·
Updated

Infosec in brief Good cybersecurity habits don't appear to qualify anyone to work at DOGE, as one Musk minion seemingly fell victim to infostealer malware. Developer and journalist Micah Lee reported last Thursday that he found a whopping 51 data breach records and four infostealer log dumps associated with DOGE employee Kyle Schutt on data breach tracking service Have I Been Pwned (HIBP) – which is unnerving as Schutt has access to sensitive government data at the Federal Emergency Management Agency. As Lee pointed out, 51 breach records on HIBP is a lot, but excusable because while Schutt’s info was found in records associated with a 2013 Adobe breach, the 2016 LinkedIn breach, and Gravatar’s 2020 breach, none of those incidents involved Schutt’s personal machines. What is attributable to a lapse of security hygiene, however, are the four infostealer logs that link to Schutt. Such logs contain usernames and passwords stolen by infostealer malware, suggesting one or more of Schutt's computers were compromised at some point. According to Lee, account credentials linked to Schutt were found in the 100GB Naz.API dump that contained 71 million unique email addresses and password combinations, the ALIEN TXTBASE stealer dump containing 284 million unique accounts, an un-named July 2024 dump collated from malicious Telegram channels, and another massive stealer log added to HIBP in January 2025. "I have no way of knowing exactly when Schutt's computer was hacked, or how many times,...

Read full article

Affected Software

4 affected components
Cisco IOS XE
Adobe Adobe
LinkedIn LinkedIn
Gravatar Gravatar
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the discovery of old credentials from a DOGE employee found in malware data dumps.

2

What security implications are discussed?

The article highlights the risks associated with poor cybersecurity practices, which can lead to credential theft.

3

What products or software are affected?

The affected software includes Cisco IOS XE, Adobe products, LinkedIn, and Gravatar.

4

Who reported the findings related to the DOGE employee's credentials?

The findings were reported by developer and journalist Micah Lee.

5

What type of malware is mentioned in the article?

The article mentions infostealer malware as the type responsible for stealing credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203