CISA Acting Director Uploaded Sensitive Files to Public ChatGPT
Madhu Gottumukkala uploaded restricted government documents to a public AI tool, triggering a Department of Homeland Security security review and the creation of DHSchat.
Acting Director of the Cybersecurity and Infrastructure Security Agency (CISA) Madhu Gottumukkala uploaded sensitive government contracting documents marked "for official use only" into a public version of ChatGPT during the summer of 2025. While the files were not classified, they were restricted from public dissemination. The activity triggered multiple automated security warnings in August, prompting the Department of Homeland Security (DHS) to launch an internal review to determine if government security was compromised.
CISA Director of Public Affairs Marci McCarthy defended the action, stating the use was "short-term and limited" and conducted under authorized DHS controls. Gottumukkala had received a temporary exception from CISA's Office of the Chief Information Officer to use the tool at a time when ChatGPT was blocked for most DHS employees. However, other DHS officials claimed Gottumukkala pressured the agency for access and subsequently abused it.
The incident occurs amidst a leadership vacuum at CISA and broader scrutiny of Gottumukkala's tenure, which includes an unsuccessful attempt to remove the agency's chief information officer and an unsanctioned counterintelligence polygraph that led to the suspension of six staff members. In response to the data exposure, CISA developed DHSchat, a private internal AI tool designed to keep sensitive information within federal networks.
Cybersecurity experts offered mixed reactions. Some argued that the detection of the uploads demonstrated high governance maturity, while others criticized the lack of a controlled environment, noting that AI experimentation should occur in sanctioned sandboxes to avoid exploitation by foreign adversaries.