The account centers on Daniel J. Berulis, who says DOGE staffers arrived at NLRB headquarters in Washington, D.C., and pressed for the creation of powerful accounts that would be exempt from normal logging. According to the excerpt, those accounts could read, copy and alter database information, and could also reduce or remove log visibility. Berulis says agency leadership instructed IT staff not to follow standard operating procedure and not to create normal records for the new accounts.

He says one of the accounts created a containerized environment on March 3, a detail that stood out because he and his colleagues did not recognize the tool in regular NLRB use. Shortly after, he observed a large spike in outgoing traffic from the agency between about 3 a.m. and 4 a.m. on March 4. After investigating with co-workers, Berulis says he concluded that roughly 10 gigabytes of data had been transferred from the NxGen case management system.

The complaint says the data set could have contained information about unions, ongoing legal cases and corporate secrets. Berulis also told senators that he did not know whether the 10 gigabytes represented the full extent of the transfer or whether the files had been compressed first, leaving open the possibility that more information moved than the initial estimate captured. The reporting does not say where the data went.

Berulis says the activity became more alarming when he saw nearly two dozen login attempts from a Russian IP address using valid credentials for a newly created DOGE account. Those attempts were blocked by the NLRB's no-out-of-country login policy. The excerpt says many of the attempts happened within 15 minutes of the account being created, which raised questions about how the credentials were exposed so quickly.

The complaint also points to other signs that normal controls had been loosened. Berulis says logs for recently created resources were missing by March 5, and Microsoft Azure's network watcher had been turned off. He also found code libraries from GitHub that the NLRB and its contractors did not normally use, including tools described as capable of helping rotate connections across many cloud IP addresses for web scraping and brute forcing.

The reporting says the matter was expected to be reported to US-CERT on March 24, but that the effort was later halted after instructions were said to have come down to drop the reporting and investigation. That is the point at which Berulis decided to speak publicly, according to the excerpt. Because the report is based on a whistleblower complaint, the allegations remain claims made by a named security architect and not findings from a completed public inquiry.