Markey Letter to SBA Administrator Loeffler on DOGE Access to SBA Systems — August 1, 2025
- Issuer
- Congressional materials
- Document type
- 2025 08 01 Markey Demands Answers To Sba Ranking Member Markey Demands Answers From Sba On
- Date
- 2025-08-01
- Case
- 2025 08 01 Markey Demands Answers To Sba Ranking Member Markey Demands Answers From Sba On Facil 01
Summary
A letter dated August 1, 2025 from Senator Edward J. Markey, Ranking Member of the Committee on Small Business and Entrepreneurship, to Kelly Loeffler, Administrator of the U.S. Small Business Administration. Citing reporting by Wired, the letter states concerns that Department of Government Efficiency (DOGE) staffers gained access to SBA information systems and the National Finance Center, which holds personally identifiable information. It recounts a February letter to Acting Administrator Everett Woodel, Jr. and the Administrator's May 21, 2025 testimony before the committee. The letter demands written answers and responsive documents by August 8, 2025 to six questions, covering what was done with the data, vetting of DOGE staffers, general counsel review under the Privacy Act, training, and login attempts from foreign IP addresses.
Summary drafted by a model from the document's text below and checked by script against that text before publication. It is a navigation aid, not a reading of what the document proves. Where AI is used
Full text
August 1, 2025
The Honorable Kelly Loeffler
Administrator
U.S. Small Business Administration
409 3rd Street, SW
Washington, DC 20416
Dear Administrator Loeffler,
Recent reporting suggests that my worst fears about the collection and nefarious repurposing
of Americans’ private, personal information by the Department of Government Efficiency
(DOGE) have been realized. Under your watch, unvetted DOGE employees with no background
in data security protocols appear not only to have gained access to the Small Business
Administration’s (SBA) information systems but used that access to infiltrate the National
Finance Center (NFC), which holds personally identifiable information (PII) collected from
several federal agencies. Yet you have shown no concern about this undermining of security
protocols established by decades-old laws. The American people deserve to know the extent to
which unvetted DOGE staffers have accessed their sensitive business and personal information
and to what end that information is now being used.
On July 30, 2025, Wired reported that DOGE operatives Edward Coristine—a 19-year-old
also known by the online alias “Big Balls”—and Donald Park—described by Wired as “a
Brazilian jiujitsu enthusiast and private equity investor”—were granted sweeping access to
SBA’s and NFC’s sensitive information systems, including the personally identifiable
information (PII) of small business owners and everyday Americans. 1 This breach of public trust
at the SBA is especially disturbing given the unique sensitivity of the PII the agency collects
from small business owners seeking to utilize its programs and services such as, according to
Wired, “employer identification numbers (EINs), North American Industry Classification
System (NAICS) numbers, and Social Security numbers.” 2
In February, I wrote Acting Administrator Everett Woodel, Jr. requesting information on
early reports that DOGE had gained access to SBA’s information systems. 3 The response was
1
Victoria Elliott, How Edward ‘Big Balls’ Coristine and DOGE Got Access to a Federal Payroll System That
Serves the FBI, Wired (June 30, 2025), https://www.wired.com/story/edward-coristine-big-balls-doge-federal-pay-
roll-system/.
2
Id.
3
Letter from Sen. Edward J. Markey, Ranking Member of the U.S. S. Comm. on Small Bus. and Entrepreneurship,
to Everett Woodel, Jr., Acting Admin., U.S. Small Bus. Admin. (Feb. 5, 2025),
https://www.sbc.senate.gov/public/_cache/files/3/c/3cb8a535-6d8f-4625-b4b5-
Page 2
dismissive, 4 and during your May 21, 2025, testimony before the Senate Small Business and
Entrepreneurship Committee, you stated that you were “proud that we are working alongside the
DOGE team, who are not partisan, but patriots and business leaders who care about the future.” 5
Now we know that, over the course of the six months since I wrote to SBA, you have allowed
DOGE to run rampant, stomping on the right to privacy and government accountability.
DOGE is stealing data and potentially spying on Americans. Federal auditors unequivocally
characterized DOGE’s operations not as proper audits but as a “heist,” warning that “none of
them have any auditing background, none have any certifications, none have any clearances.” 6
The auditors raised alarms that DOGE may be attempting to exfiltrate and consolidate sensitive
PII—including Social Security, tax, immigration, and labor records—to build a comprehensive
“master” database on Americans. 7 Consolidating information in this manner could potentially
enable political targeting or interference with small businesses or demographic groups. 8 It is
unacceptable that individuals such as Coristine and Park—who lack any security clearances or
qualifications—were allowed to access systems holding small businesses’ most sensitive,
confidential data.
Let me be clear: DOGE is not a legitimate government agency. Under no circumstances
should any DOGE staffers have access to small business owners’ PII. As SBA Administrator,
you are accountable to Congress and to the American people. Concealing what DOGE did at
SBA is dangerous, unpatriotic, and an abdication of your responsibility. I demand written
answers to the following questions, and responsive documents, by August 8, 2025.
1. What did DOGE, including Edward Coristine and Donald Park, do with the sensitive
information they stole from the SBA and the American people?
2. Has DOGE centralized the information stolen from SBA and other federal agencies? If
so, where is this data stored? What is the intent behind centralizing Americans’ data?
3. What steps did SBA take to authenticate, vet, or supervise DOGE staffers? Were
background checks or government credentials verified? If so, what level of clearance did
Edward Coristine, Donald Park, and other DOGE staffers hold?
4. Did SBA’s general counsel review and offer an opinion on DOGE’s actions with respect
to their legality under the Privacy Act, Federal Information Security Modernization Act,
the Computer Matching and Privacy Protection Act, and other federal statutes that govern
7bef501cd114/8CFC76B89244584B7A46E3BC0A75165B524652E89D7120A82B648AE2A06334D3.02-05-25-
letter-sba-doge.pdf.
4
Letter from Everett M. Woodel Jr., Acting Admin., U.S. Small Bus. Admin., to Senator Edward J. Markey,
Ranking Member, U.S. S. Comm. on Small Bus. and Entrepreneurship (Feb. 11, 2025) (on file with committee).
5
Fueling America’s Manufacturing Comeback: Hearing Before the S. Comm. On Small Bus. And Entrepreneurship,
119th Cong. (2025) (statement of the Hon. Kelly Loeffler, Admin., U.S. Small Bus. Admin).
6
Victoria Elliott, ‘It’s a Heist’: Real Federal Auditors Are Horrified by DOGE, Wired (Mar. 18, 2025),
https://www.wired.com/story/federal-auditors-doge-elon-musk/.
7
Makena Kelly & Victoria Elliott, DOGE Is Building a Master Database to Surveil and Track Immigrants, Wired,
(Apr. 18, 2025), https://www.wired.com/story/doge-collecting-immigrant-data-surveil-track/.
8
Melissa Angell, House Dems Raise Alarm Over DOGE’s Access to SBA Systems, Fearing Musk Could Target
Entrepreneurs, Inc. (Feb. 5, 2025), https://www.inc.com/melissa-angell/house-dems-raise-alarm-over-doges-access-
to-sba-systems-fearing-musk-could-target-entrepreneurs/91143402?utm_source=chatgpt.com; Jenna McLaughlin, A
whistleblower’s disclosure details how DOGE may have taken sensitive labor data, NPR (Apr. 15, 2025),
https://www.npr.org/2025/04/15/nx-s1-5355896/doge-nlrb-elon-musk-spacex-security.
Page 3
payment systems, privacy protections, interagency data sharing, and federal audit
standards?
5. What data privacy and protection trainings are SBA employees required to undergo? Did
DOGE staffers at SBA undergo the same training?
6. Since DOGE accessed SBA’s information systems, have there been attempted logins to
them associated with foreign IP addresses? If so, from what countries? What is SBA
doing to mitigate these potential breaches?
I look forward to receiving your answers so that the American people get the accountability
and transparency they deserve on this troubling matter.
Sincerely,
Edward J. Markey
Ranking Member, Committee
on Small Business and
Entrepreneurship
File and source
- File
- 2025-08-01_markey-demands-answers-to-sba_ranking-member-markey-demands-answers-from-sba-on-facil_01.pdf
- Size
- 352,663 bytes
- SHA-256
- 23b6ef61c7275d0586a9c206770cb4e31d7c0e5fa3805497fca9e495de35625e
- Original
- No public link identified.