EPISODE · Jun 29, 2026 · 20 MIN
They Sealed Your Records. Then Sold Them.
from The Experience of Adoption · host Thoughtless Delineation
This is a free preview of a paid episode. To hear more, visit thoughtlessdel.substack.comA Forensic Investigation into the DOGE–SSA Breach, the $29 Billion Procurement Network, and Why Abolition Is the Only FixThere is a database that has existed since 1936. It holds the Social Security number application records of every person who has ever been issued an SSN in the United States — roughly 500 million living and dead. It is called the Numident. Inside each record is a father’s name and a mother’s maiden name, captured at the moment of original application, before any court order rewrote the facts of a person’s origins.For most Americans, that detail is incidental — a genealogical footnote, mildly interesting.For adoptees in sealed-records states, it is one of the only remaining bureaucratic traces of biological parentage that the state’s own identity-erasure machinery did not manage to reach.In March 2026, a whistleblower alleged that a former DOGE software engineer named John Solly had that database on personal removable media — and planned to hand it to his new private employer.The sealed record and the exfiltrated record are the same record.That sentence is this article’s thesis. Everything that follows is evidence.And then — because evidence without structural analysis is just spectacle — one more sentence:The system that created the sealed record also created the conditions that made the exfiltrated record worth stealing.That is the sentence the independent journalists covering this story have not written. Not one of them.PART ONE — THE EVIDENCE RECORDThe Chain of AccessDOGE’s penetration of the Social Security Administration did not begin with John Solly, and it did not begin with a portable drive. It began in February 2025, when approximately twelve DOGE operatives were embedded inside SSA headquarters. They did not appear on the agency’s organisational chart. Their roles were not communicated to SSA staff. Their legal authority to access federal systems containing the private records of every American alive was, at best, contested — and eventually ruled by a federal court to be impermissible.Wired identified the ten known operatives by name from internal Microsoft Teams directories: Akash Bobba, Scott Coulter, Marko Elez, Luke Farritor, Antonio Gracias, Gautier Cole Killian, Jon Koval, Nikhil Rajpal, Payton Rehling, and Ethan Shaotran. John Solly was among the twelve.From the moment they arrived, the pattern was the same: requests for access that exceeded what any legitimate fraud-detection mandate could justify; approval by DOGE-aligned officials who had been installed specifically to grant that access; and the systematic bypassing of career security staff whose job was to prevent exactly this.March 2025 — The Court Order and the Data SearchOn 20 March 2025, a federal court issued a temporary restraining order barring DOGE from continued access to SSA’s sensitive data systems.On 24 March 2025 — four days later — a DOGE team member ran searches of SSA’s master database. That same day, a different DOGE member signed a “Voter Data Agreement” with True the Vote — a political advocacy organisation whose stated aim, admitted in a subsequent DOJ court filing, was “to find evidence of voter fraud and to overturn election results in certain States.” The agreement was signed in his capacity as an SSA employee.The DOJ acknowledged in January 2026 that these actions were “likely inconsistent with SSA policy” and “non-compliant with the temporary restraining order.” No charges have been filed.June 2025 — The Supreme Court Clears the PathOn 6 June 2025, the Supreme Court ruled 6–3 in SSA v. AFSCME to restore DOGE’s access to Social Security data in full. Justices Kagan, Sotomayor, and Jackson dissented, writing that the majority had granted emergency relief despite the government’s “failure to show any need or any interest in complying with existing privacy safeguards.”Four days after that ruling, a former DOGE employee requested that SSA copy its entire Numident database to a private cloud environment. The request was approved by Aram Moghaddassi, a DOGE-affiliated hire installed as co-chief information officer. His stated rationale: “I have determined the business need is higher than the security risk.”Career cybersecurity officials inside SSA had rated the request “very high risk.” An internal risk assessment explicitly recommended that “production data should not be used.” Both assessments were overridden. The data was moved to an unauthorised Cloudflare server. SSA could not subsequently access, audit, or confirm its security status.SSA’s chief data officer, Charles Borges, was not informed. He was not consulted. He learned of it through other means.August 2025 — Borges Files and ResignsOn 26 August 2025, Borges filed a formal whistleblower complaint alleging that DOGE-affiliated officials had copied the Numident to a self-administered cloud environment “lacking any security oversight from SSA or tracking to determine who is accessing or has accessed the copy of this data.” SSA’s internal risk assessment placed the probability of catastrophic breach at between 35 and 65 per cent.Three days after filing, Borges resigned. SSA denied the allegations. That denial was subsequently reversed in court.October 2025 — Solly Departs for LeidosIn October 2025, John Solly left SSA and joined Leidos — a Fortune 500 defence and government services contractor — as Chief Technology Officer of its health IT division. Leidos holds a five-year SSA contract worth up to $1.5 billion. In January 2026, Leidos announced a partnership with OpenAI for federal health AI deployment — six days after the DOJ admitted DOGE had misused SSA data.Solly’s personal website, taken offline in March 2026, listed his SSA work as including “Digital SSN,” “Death Master File cleanup,” and “SSN verification API (EDEN 2.0).”January 2026 — The DOJ AdmissionOn 16 January 2026, the DOJ filed documents acknowledging that DOGE members had accessed and shared sensitive Social Security data without agency awareness, had used an unauthorised server, and may have violated the Privacy Act, FISMA, and the Computer Fraud and Abuse Act.No prosecutions followed.March 2026 — The Removable DriveOn 6 March 2026, SSA’s OIG formally opened an investigation of allegations that a former DOGE employee had taken copies of the Numident and the Death Master File on personal removable storage to his new employer. On 12 March 2026, Wired identified the subject as John Solly.The whistleblower’s account: Solly told multiple colleagues he possessed both databases. He had at least one on a personal drive. He asked a colleague for help transferring data to a personal computer for “sanitisation” before upload to Leidos. When the colleague raised concerns about criminal liability, Solly reportedly said he expected a presidential pardon.Solly denies all wrongdoing. Leidos found no evidence of SSA data on its networks. The OIG investigation is ongoing.PART TWO — THE NUMIDENT AND THE ADOPTEEThe Sealed Record and the Exfiltrated Record Are the Same RecordAdoption in the United States has always functioned not merely as a family-creation system, but as an identity-management system. The amended birth certificate is not only a social instrument; it is a data instrument. It reallocates relational truth — changing who can access origin information, who controls lineage, and who possesses legal standing over biological fact.The sealed-records regime transformed human identity into administratively managed information decades before Silicon Valley discovered the commercial value of data extraction. When the state sealed an adoptee’s original birth certificate, it was not protecting the adoptee. It was asserting custodianship over origin itself — reserving the right to determine who may access biological truth, under what conditions, and for whose benefit.The Numident fell outside that custodianship. Created by a different agency under a different mandate, it recorded the father’s name and mother’s maiden name at the moment of SSN application — before adoption amendment could reach it. For many adoptees, it is the only surviving federal record that predates the erasure.In forty states, adult adoptees cannot access their own original birth certificates without a court order or an intermediary process that can cost hundreds of dollars. In eighteen states, a court order is the only route.The Numident was never sealed. It is the record the Architecture of Silence forgot.The Asymmetry of AccessThe piece of analysis mainstream coverage has entirely avoided: adoptees are denied access to origin records in the name of privacy. Institutions retain access in the name of administration. Commercial actors gain access in the name of efficiency. The state gains access in the name of governance.The only party systematically excluded — by law, by court order, by institutional design — is the person whose identity is being governed.A former DOGE engineer with self-described “God-level” access allegedly walked the biological parentage data of 500 million Americans out on personal removable media. The state that seals biological identity from the people whose identity it is had no corresponding reluctance about placing it in commercial hands.That is not a contradiction. It is a structural disclosure.PART THREE — THE COMMERCIAL LOGICLeidos is not simply a government contractor. It is one of the largest health IT companies in the United States, with a declared strategy — “NorthStar 2030” — built around transforming large volumes of data into actionable insights. Its health division generates annual revenues exceeding $1.1 billion.The Numident’s value to a health IT company is not primarily the names. The names are the keys. What lies beneath them is the relational architecture: parent-to-child chains, biological kinship networks, the identity graph of the United States extending back to 1936.The “sanitisation” step Solly allegedly described — stripping direct identifiers before upload — is precisely the technique used to create de-identified datasets that remain commercially exploitable while nominally complying with privacy law. De-identified data is not anonymous data. Re-identification from relational structure is a documented, solved problem in computer science.If the allegations are true, what occurred was the privatisation of one of the most sensitive identity archives in American history. Not through legislation. Not through public debate. Through personal removable media in a jacket pocket.The biological parentage of adoptees — data the state legally withholds from the adoptees themselves — would have entered that commercial asset class along with everything else.PART FOUR — THE OVERSIGHT FAILUREAt the time of writing, no body with actual prosecutorial authority is independently investigating this breach. The DOJ is controlled by the same executive branch that installed DOGE and authorised its access. Congressional Democratic investigators are the minority — no subpoena power. The SSA OIG reports to a DOGE-aligned commissioner. The GAO is an audit body, not a prosecutorial one.Solly reportedly expected a presidential pardon if his actions were found unlawful. That is not bravado. It is a precise legal calculation from someone who understood the political structure within which he was operating.The data was not taken despite political cover. It was taken because political cover was understood to exist.There is one more entry in this timeline that mainstream coverage has not connected to any of the above. On 8 January 2026 — before the OIG opened its investigation, before Wired named Solly, before any congressional letter had been sent — SSA filed new System of Records Notices in the Federal Register expanding the routine uses of its data systems to include the Office of the President, law enforcement, and third parties. Effective 9 February 2026.This is not incidental. This is the administrative legalisation of what DOGE had already been doing unlawfully. The sequence is: unlawful access → DOJ admission → no charges → administrative legalisation → OpenAI partnership.This is not dysfunction. This is policy.PART FIVE — WHAT THIS MEANS FOR ADOPTEESCharles Borges told NPR in March 2026: “Once that data has left the building, you cannot close Pandora’s box again.”He is right. And the implication for adoptees is specific:Every adoptee in a sealed-records state should understand what this means in concrete terms. The state will not tell you your biological parents’ names. The court that finalised your adoption will not unlock that record without a process that costs money, time, and, in many jurisdictions, the consent of people who may not want to be found.That same system placed the same information in an unaudited cloud environment with a 65 per cent probability of catastrophic breach. Then it allegedly allowed it to leave the building on personal removable media headed to a defence contractor with an OpenAI partnership. Then it expanded the routine uses of its data systems to include the Office of the President and third parties — and called that an administrative update.The sealed record was never sealed for the adoptee’s benefit. It was sealed to protect the institution of adoption — to maintain the legal fiction, to prevent inconvenient biological truths from disrupting the adoptive family arrangement, to serve the interests of agencies, courts, and adoptive parents rather than the person whose identity was being managed.The DOGE breach did not create that condition. It illuminated it — with unusual precision.PART SIX — THE CONNECTION THE JOURNALISTS AREN’T MAKINGIndependent journalists are covering this story in lanes. The DOGE breach is a government accountability story. The SSA data is a privacy story. The Leidos–OpenAI partnership is a tech story. The congressional letters are a democracy story.None of them have written this sentence: the breach was made possible by the same system that made the data worth stealing.Here is what a serious investigation of the current US political situation would find if it followed the structure instead of the symptoms.In the United States, prospective adoptive parents now outnumber available infants by more than 40 to 1. The total domestic adoption sector is valued at $29.4 billion. This supply-demand imbalance does not resolve itself through goodwill. It resolves through procurement infrastructure.H.R. 9218 — the Protecting Adoption Act, introduced by Mary Miller of Illinois — codifies cash transfers for housing and utilities as “adoption promotion,” creating a pre-payment framework for human beings. The implicit contract: we paid your rent; you owe us your child. Legislative trafficking in all but name.At the same time, the Bureau of International Labor Affairs terminated over $726 million in anti-trafficking grants. Zero Tolerance separated families at the border and reclassified children as unaccompanied minors, generating a fresh stream into domestic pipelines. Attorney Paul Petersen ran a baby mill across three states using Marshallese women and $814,000 in Medicaid fraud. Former Representative Matt Shea used an unlicensed NGO to attempt the transfer of 62 Ukrainian children from Mariupol, bypassing the Hague Convention under a humanitarian rescue narrative.These are not separate stories about bad actors. They are sequential chapters of the same procurement operation.And the National Council For Adoption — founded in 1980 by William Pierce with the documented mission of defeating adoptee records access — received approximately $20.8 million in federal grants between 2001 and 2005, during which period it spent $1.72 million lobbying specifically to maintain sealed records. That suppression loop did not end in 2005. The NCFA holds an active partnership with the HHS Children’s Bureau as of 2025/2026. Taxpayers are still funding the organisation built to keep adoptees from their own origins. The lock is still being paid for.Now follow the logic:The sealed record is what created the information asymmetry. The information asymmetry is what gave the Numident its commercial value. If the state had never issued amended birth certificates — if adoption law did not include the legal fiction of “as if born to” — the Numident would be an ordinary genealogical database. The parent fields would match the birth records. There would be no discrepancy to exploit, no hidden biological truth to extract, no sealed-record shadow economy for a DOGE operative to monetise.The adoption system manufactured the scarcity. DOGE exploited it.The journalists covering DOGE as a government accountability story and the journalists covering the $29 billion adoption industry as a consumer protection story are covering the same extraction operation from two different angles. They have not noticed they are in the same room.PART SEVEN — THE ONLY FIXReform is the wrong ask.It has always been the wrong ask. Reform says: keep the system, adjust the parameters, add oversight mechanisms, tighten the regulations. Reform says: the adoptee should have better access to records, the agencies should be better licensed, the attorneys should be better regulated, the data should be better protected.Reform does not ask what the system is for. It asks how to make the system less harmful while preserving the system’s existence. That is the political logic of an institution with $29.4 billion in annual revenue and congressional allies who receive adoption agency donations. Reform is what the adoption industry tolerates so it does not have to face abolition.Abolition asks the structural question: what problem does adoption solve, and does it solve it, and for whom?The answer is documented: In the United States, adoption is not primarily finding families for children who need them. It is finding children for families who want them. The 40-to-1 imbalance is not a demographic accident. It is the market condition the procurement infrastructure was built to service. Poverty-coerced relinquishment. Clinical coercion in agency-run housing. Cash-App payments. Legislative pre-purchase. Immigration enforcement as supply-chain management.The same children who would remain with their birth families if those families had adequate housing, healthcare, and economic support are instead processed through a $29.4 billion industry that begins with Google Pay-Per-Click campaigns targeting women in crisis and ends with a sealed birth certificate that transfers origin to the highest bidder.Abolition does not mean children in need of care are abandoned. It means the legal mechanism of adoption — the amended birth certificate, the “as if born to” doctrine, the sealed records regime — is replaced with legal guardianship frameworks that protect children without erasing their biological identity, without manufacturing a legal fiction, without creating the information asymmetry that built both the sealed-records industry and the commercial value of the data DOGE just allegedly handed to a defence contractor.If the “as if born to” doctrine does not exist, amended birth certificates do not exist. If amended birth certificates do not exist, the Numident’s parent fields are not in shadow. The commercial value of biological identity data — the specific, exploitable asymmetry between what the state knows and what the adoptee is permitted to know — collapses. EDEN 2.0 becomes an administrative tool, not a covert back-channel to sealed origins.The independent journalists covering the DOGE breach should be writing this. The commentators covering family separation, reproductive coercion, immigration enforcement, and data sovereignty should be writing this. They are not. They are covering symptoms in the lanes they were assigned, producing outrage that dissipates without ever reaching the structure.Adoption abolition is not a niche position inside the adoptee rights conversation.It is the structural solution that sits underneath every story they are separately failing to connect.FORENSIC SUMMARY — THE CONFIRMED EVIDENCE CHAINFebruary 2025 — 12 DOGE operatives embedded at SSA, including John Solly. Confirmed — Wired, internal documents.20 March 2025 — Federal court issues TRO barring DOGE from SSA data access. Confirmed — court record.24 March 2025 — DOGE member searches Numident; second member signs Voter Data Agreement with True the Vote. Confirmed — DOJ court filing January 2026; congressional Democrats letter February 25, 2026.10 June 2025 — Solly requests Numident copy to private cloud; Moghaddassi approves. Confirmed — Borges complaint, congressional letters.June 2025 — Numident moved to unauthorised Cloudflare server. Confirmed — DOJ admission, Borges complaint.6 June 2025 — Supreme Court 6–3 restores DOGE access. Confirmed — court record.August 2025 — SSA internal risk assessment: 35–65% probability of catastrophic breach. Confirmed — congressional reporting.26 August 2025 — Borges files whistleblower complaint; names Solly and Russo. Confirmed — Government Accountability Project.29 August 2025 — Borges resigns. Confirmed.October 2025 — Solly departs SSA; joins Leidos as CTO, health IT. Confirmed — résumé, Wired.16 January 2026 — DOJ admits DOGE likely violated policy, court order, possibly law. Confirmed — DOJ filing, AFSCME v. SSA.8 January 2026 — SSA files new SORNs expanding data-sharing routine uses to include Office of the President, law enforcement, third parties; effective 9 February 2026. Confirmed — Federal Register Vol. 91.22 January 2026 — Leidos announces OpenAI partnership. Confirmed — Leidos press release.6 March 2026 — SSA OIG formally opens investigation. Confirmed — OIG letter to Congress.12 March 2026 — Wired identifies Solly; names Leidos. Confirmed — Wired, multiple sources.June 2026 — No charges filed; no special counsel; investigation ongoing. Confirmed.Alleged but unconfirmed: that Solly successfully transferred data to his personal computer; that data reached Leidos networks (Leidos forensics found no evidence); the architecture and current status of EDEN 2.0.*Sources: Washington Post (Kornfield & Dwoskin, March 2026), Wired (Elliott & Kelly, March 2026), NPR (March 2026), DOJ court filings in AFSCME v. SSA, House Oversight Committee Democratic letters, Senate HSGAC letters, Garcia-Morelle-Larson letter to True the Vote (February 25, 2026), Government Accountability Project, FRONTLINE (Glaser), Federal Register Vol. 91 (January 8, 2026), NCFA federal grant records, H.R. 9218 legislative text, Leidos SEC filings, NARA Numident FAQ, Adoptee Rights Law Center.**All allegations regarding John Solly remain unproven. Solly denies all wrongdoing. Leidos found no evidence of data on its networks. The SSA OIG investigation is ongoing.*Use at your own discretion PAID SUBSCRIBER ACCESS TO REPORTSOr contact me directlyThis Substack is reader-supported. To receive new posts and support my work, consider becoming a free or paid subscriber.
Embed this episode
NOW PLAYING
They Sealed Your Records. Then Sold Them.
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.