The receipts / Privilege separation

CISA: the cybersecurity chief and the blocked tool

Mid-2025, disclosed January 2026 Caught by automated endpoint alerts

The acting director of the federal cybersecurity agency uploaded at least four sensitive, for-official-use-only contracting documents into public ChatGPT, using a special permission he had requested while the tool was blocked for the rest of the staff. Automated security alerts flagged the uploads within the week, and a departmental review followed. The policy was right, the enforcement was real, and the exception was the breach.

Primary source: TechCrunch

The record

What the verified record says.

Organizations
Cybersecurity and Infrastructure Security Agency (CISA); US Department of Homeland Security
When
July 2025Resolved January 27, 2026
Failure class
Data leak data-leak
Discovered by
The deployer, through its own monitoring deployer-monitoring Caught by the organization running the AI
Missing control
Privilege separation. Permissions enforced by infrastructure, not by instructions. Full definition and the other incidents in this group Watch this kind of control catch a planted failure
What would have caught it
Endpoint alerts on uploads to public AI services, which is the control that worked here.
Sources
Verification
Confirmed: the claims held as first researched. The uploads were mid-July to early August 2025 and were caught by automated alerts within about a week. January 2026 is the disclosure date, not the incident date, and the outcome of the department's harm review was not disclosed. Verified against the primary source on August 12, 2026. Published on this site August 13, 2026, updated September 1, 2026.

This record is one of 26 in The receipts, each checked against a primary source before it is published. How the list is built