CISA Chief Uploaded Sensitive Documents into Public ChatGPT
The Cybersecurity and Infrastructure Security Agency (CISA) encountered a security incident when its acting director uploaded sensitive contracting documents marked "for official use only" into the public version of ChatGPT in August 2025, triggering…
The Cybersecurity and Infrastructure Security Agency (CISA) encountered a security incident when its acting director uploaded sensitive contracting documents marked "for official use only" into the public version of ChatGPT in August 2025, triggering automated security alerts. This action prompted an internal review to evaluate potential impacts on national security.
The interim head of CISA, Madhu Gottumukkala, who has been in position since May 2025, received special permission from the agency's Chief Information Officer to utilize the AI tool, despite its blockage for other Department of Homeland Security (DHS) staff. While the uploaded documents were not classified, they contained sensitive information not intended for public dissemination.
CISA’s cybersecurity sensors detected the uploads, leading to discussions between Gottumukkala and senior DHS officials, including the then-acting general counsel and the agency's Chief Information Officer. DHS policy requires investigations into such exposures to assess causes and consider actions such as retraining or security clearance revocation.
This action prompted an internal review to evaluate potential impacts on national security.
Public ChatGPT shares user inputs with OpenAI, posing a risk of sensitive data being utilized in training models accessible to adversaries. This is critical for CISA, whose mission includes countering threats from state-backed hackers. CISA spokesperson Marci McCarthy stated that the use of ChatGPT was under "DHS controls" with a "short-term and limited" exception, aligning with the agency’s AI commitment as per the executive order.
In contrast, approved DHS tools, like DHSChat, ensure data storage on federal networks, with all employees trained in handling sensitive documents.
Gottumukkala's tenure has been scrutinized, with notable incidents including placing six career staff members on leave following an unsanctioned counterintelligence polygraph failure. He denied the premise of a "failed test" during testimony. The review's outcome remains undisclosed.
Based on reporting by Cyber Security News.
