by

Top US spook fed sensitive files to public ChatGPT

POLITICO has reported that CISA acting director Dr Madhu Gottumukkala uploaded contracting files marked “for official use only” in the summer of 2025, triggering automated security warnings designed to stop government data from leaking off federal networks.

The slip looked worse because Gottumukkala had asked CISA’s Office of the Chief Information Officer for special permission to use ChatGPT soon after arriving in May 2025, when the app was blocked for other DHS staff.

None of the uploaded files were classified, according to four DHS officials, but “for official use only” is still sensitive and not meant for public release.

Cybersecurity sensors at CISA flagged the uploads in August 2025, with one official noting multiple warnings in the first week of August alone.

Two officials said DHS senior staff conducted an internal review to assess whether the exposure compromised government security, though it is unclear what the review concluded.

CISA, director of public affairs Marci McCarthy said Gottumukkala “was granted permission to use ChatGPT with DHS controls in place,” and that “this use was short-term and limited.”

McCarthy said the agency was committed to “harnessing AI and other cutting-edge technologies to drive government modernisation and deliver on Donald Trump’s executive order removing barriers to America’s leadership in AI.

Her email also pushed back on the timeline: “Acting Director Dr Madhu Gottumukkala last used ChatGPT in mid-July 2025 under an authorised temporary exception granted to some employees. CISA’s security posture remains to block access to ChatGPT by default unless granted an exception.”

Gottumukkala is the senior-most political official at CISA, the agency meant to harden federal networks against state-backed attackers from countries including Russia and China.

Material uploaded to the public version of ChatGPT is shared with its owner, OpenAI, and POLITICO noted that the app has more than 700 million active users.

Other DHS-approved tools, including the department’s own DHSChat, are configured to stop prompts and documents from leaving federal systems.

All federal staff are trained on handling sensitive material, and DHS policy requires investigating the “cause and effect” of exposure and the “appropriateness” of any administrative or disciplinary action.

Two officials said Gottumukkala spoke with DHS leaders after the activity was detected to review what he uploaded, with DHS then-acting general counsel Joseph Mazzara and DHS chief information officer Antoine McCord both involved.

The four officials said Gottumukkala met with CISA chief information officer Robert Costello and chief counsel Spencer Fisher in August 2025 regarding the incident and the proper handling of “for official use only” material.

Gottumukkala has led CISA in an acting capacity since May 2025, after DHS Secretary Kristi Noem appointed him deputy director, while Trump’s nominee, DHS special adviser Sean Plankey, remains pending Senate confirmation.

POLITICO linked the mess to a broader run of turbulence, including an “unsanctioned” counterintelligence polygraph episode that saw at least six career staff placed on leave.

During congressional testimony last week, Gottumukkala twice told Rep. Bennie Thompson that he did not “accept the premise of that characterisation.”

He tried to oust Costello before other political appointees intervened, which is a bold way to run a cyber agency that cannot keep its own house in order.

 

TOPICS:
chatgpt  ·  cisa  ·  data security  ·  dhs  ·  government cybersecurity  ·  madhu gottumukkala  ·  openai  ·  sensitive documents  ·  trump administration

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews