Lady Justice statue holding scales against a blurred background
Photo via Unsplash

TL;DR: On April 10, 2026, the Fourth Circuit Court of Appeals vacated the injunction that restricted DOGE’s access to Social Security Administration data, even though the court’s own opinion called the government’s admissions “alarming.” Those admissions include a DOGE employee signing a voter data agreement with a political advocacy group trying to overturn election results, two DOGE associates accessing sensitive data after a court order told them to stop, and an unauthorized server used to handle citizen records. The case goes back to a district court judge who now has the corrected record, and plaintiffs have moved for discovery and depositions. The legal fight is far from over.

The Fourth Circuit Said “Alarming” Twice. Then Sided With DOGE Anyway.

On April 10, Judge Toby Heytens wrote an 88-page majority opinion for the Fourth Circuit in AFSCME v. Social Security Administration. His conclusion: the four unions representing 7 million members couldn’t prove “irreparable harm” sufficient to keep the injunction in place [1].

His reasoning: the unions could still sue for monetary damages under the Privacy Act or seek a permanent injunction ordering DOGE to destroy illegally obtained data. Those future remedies, the court decided, made emergency protection unnecessary [2].

That logic works if you believe data, once copied to an unauthorized server and shared with a political group, can be meaningfully “destroyed.” Judge Robert King didn’t buy it.

“SSA and the other defendants provided patently false information to the district court,” King wrote in dissent. He argued the government deserved “no benefit of the doubt” given its track record in this case [2] [3].

Judge Andrew Wynn joined the dissent, criticizing the Supreme Court’s earlier unexplained order staying the original injunction without providing any reasoning [3].

A DOGE Employee Signed a Deal to Share Your Data With a Political Group

Here’s what the government admitted in a January 16, 2026 “Notice of Corrections to the Record”, a filing that basically said “everything we told you before was wrong” [4]:

A DOGE employee signed a “voter data agreement” in March 2025 with an unnamed political advocacy group. The agreement’s stated purpose: “to find evidence of voter fraud and to overturn election results in certain states” [4] [5].

Read that again. Someone with access to Social Security Administration records (names, Social Security numbers, birthdates, addresses, employment histories, financial data, medical records) signed up to feed that data to a political operation [1] [3].

The government hasn’t named the group. It hasn’t said how much data was shared. It hasn’t explained how an employee with access to the personal information of hundreds of millions of Americans was allowed to sign such an agreement in the first place.

Judge Heytens called these revelations “alarming and raise serious questions about [the government’s] earlier conduct.” Then he vacated the injunction [1].

They Kept Accessing Data After a Court Said Stop

The violations didn’t end with the voter data deal.

Two DOGE associates accessed sensitive SSA data after a March 2025 temporary restraining order told them to stop. The government eventually admitted this, too [1] [2].

DOGE used an unauthorized server to handle Social Security data, outside official SSA systems and protocols. The Social Security Administration itself still doesn’t know the full scope of what DOGE accessed and shared [1] [5].

A former DOGE associate allegedly planned to take citizen data with him to a government contractor position. The Fourth Circuit called this “even more alarming” than the voter data agreement [1].

And an earlier whistleblower revelation: an ex-DOGE engineer saved sensitive data on a personal thumb drive [3].

At every step, the pattern is the same. Access data you shouldn’t have. Copy it somewhere you shouldn’t. Share it with people who shouldn’t see it. Get caught. File a “correction.” Keep the access.

Discovery Is Open. That’s Where It Gets Interesting.

The case goes back to Judge Ellen Lipton Hollander in the District of Maryland. She now has the corrected record, the admitted TRO violations, the Cloudflare server disclosure, and the voter data agreement. All of it [3] [4].

Democracy Forward, representing the plaintiff unions, filed a motion for limited discovery and depositions to investigate “unlawful DOGE access to Social Security data amid misstatements, misrepresentations, and omissions made to the court” [4].

Discovery means subpoena power. It means sworn testimony. It means the government has to hand over documents it would rather keep quiet.

The questions that need answers:

  • Which political group received SSA data? What did they do with it?
  • What was on the unauthorized server? Who had access?
  • What data did the two associates access after the restraining order?
  • Where did the ex-DOGE engineer’s thumb drive data end up?
  • Does SSA actually know the full scope of the breach, or are more “corrections” coming?

The Fourth Circuit took away the shield. Discovery hands the plaintiffs a flashlight.

What Data Are We Talking About?

SSA databases contain the most sensitive information the federal government holds on ordinary Americans [3]:

  • Social Security numbers
  • Full names and birthdates
  • Driver’s license numbers
  • Home addresses
  • Employment and wage histories
  • Financial records
  • Medical records
  • Family court documents

This isn’t metadata. It’s the full picture of someone’s life. And DOGE had unsupervised access to it while sharing it with a political group and copying it to unauthorized servers.

What Happens Next

The injunction is gone, but the lawsuit isn’t. The Fourth Circuit sent the case back for full proceedings on the merits, not just emergency measures. That means a trial, potentially, on whether DOGE violated the Privacy Act [2].

The Privacy Act makes it illegal for federal agencies to disclose personal records without consent. The penalties include actual damages, attorney’s fees, and injunctive relief. If the discovery phase confirms what the “corrections” suggest, the government faces liability for every affected record [3].

The four plaintiff unions (AFSCME, AFL-CIO, Alliance for Retired Americans, and the American Federation of Teachers) represent 7 million members. Their statement after the ruling: they “look forward to continuing this case in the district court, seeking discovery, and getting to the bottom of this harmful conduct” [4].

The court called the government’s behavior alarming. The government’s own filings confirmed lies to the court. And now the people asking questions get to do it under oath.

The injunction was the guardrail. Discovery is the investigation.

What You Can Do

  • Freeze your credit: If DOGE had access to SSA records, your Social Security number may be compromised. Our guide covers the steps
  • Monitor your SSA account: Check my Social Security for unauthorized changes to your contact info, direct deposit, or benefits
  • Contact your representatives: Ask whether they support the Government Surveillance Reform Act, a bipartisan bill from Sen. Mike Lee that would add warrant requirements to bulk data access
  • Follow the case: Democracy Forward’s case page tracks filings and developments

References

  1. Nextgov: Appeals Court Removes Limits on DOGE Access to SSA Data Despite ‘Alarming’ Revelations (April 2026)
  2. Government Executive: Appeals Court Clears Way for DOGE Access to Social Security Data Despite New Red Flags (April 2026)
  3. Courthouse News: Fourth Circuit Bows to Supreme Court in DOGE Social Security Data Fight (April 2026)
  4. Democracy Forward: Court Filing: Discovery and Depositions to Investigate DOGE Access to Social Security Data (2026)
  5. Democracy Docket: DOGE’s Secret Voter Data Deal Was ‘Alarming,’ Court Finds (April 2026)