Summary

  • Kyle Schutt, a software engineer who works for the Department of Government Efficiency and the Cybersecurity and Infrastructure Security Agency (CISA), has had his login credentials leaked multiple times since 2023, according to journalist Micah Lee.
  • The leaks came from info-stealer malware, which typically obtains credentials by hacking into devices through trojanised apps, phishing, or software exploits.
  • Schutt’s credentials have appeared in logs from these stealers, which are then sold on or shared publicly.
  • Lee says that the leaks are from accounts associated with Schutt, including a Gmail account, which has been breached 51 times, as tracked by breach notification service Have I Been Pwned.
  • These breaches have included major hacks, such as those of Adobe, LinkedIn and Gravatar.
  • Given Schutt’s role at CISA, where he has access to sensitive information regarding critical US infrastructure, the repeated breaches are a serious cause for concern.

By Dan Goodin

Original Article