That warning was not theoretical. According to Brinkley — an information system security officer who oversaw firewall rule changes and network intrusion detection and prevention while working for a government contractor — developers quietly persuaded decision-makers to alter a firewall rule that briefly removed a hard separation between a low-security commercial datacenter and a classified datacenter housing production servers. The consequence: a provisioning path that could be used to reach a production server holding 50 million immigration records from a network accessible to thousands of VPN users.
Joe Brinkley's demonstration
Brinkley says he discovered the change after returning from vacation. To make his point, he arranged a demonstration with a company colleague and a government representative. Tethering his laptop to his cellphone, he logged into the development server over the commercial datacenter VPN and — to emphasize control — turned that dev box on and off. Then, using the exact same VPN connection, he accessed the production server and controlled it. That production server, Brinkley noted, contained roughly 50 million records about immigration: who was coming to the country and who those people stayed with.
Developers, the Change Acceptance Board, and the firewall rule
Brinkley described a familiar operational pressure: developers wanted to make it easier to move code from a low-security test environment to production. In the early 2010s, the practice used a provisioning server to deploy code. Historically, a strict firewall had separated the classified datacenter (production) from the non-classified datacenter (development). While Brinkley warned the Change Review Board that opening the path was a “very bad idea,” the developers who wanted the change spoke directly to the Change Acceptance Board during his absence and succeeded in having the rule altered.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadCommercial datacenter VPN shared with Microsoft and Oracle
Brinkley emphasized another specific operational detail: the VPN in question was provided by the commercial datacenter, not the government. That same VPN connection made other non-governmental tenants — the story names Microsoft and Oracle as examples — accessible through the same link. Thousands of people had access to the commercial datacenter’s VPN; by contrast, only dozens were supposed to be able to reach the classified government datacenter. The rule change therefore risked widening access to production servers from a broadly accessible network.
Authentication gaps: no MFA and low password standards
The systems still required usernames and passwords, but Brinkley highlighted additional weaknesses. At the time, there was no multi-factor authentication protecting access to the production servers, and password standards were low. That left open attack vectors such as credential guessing or brute-force attacks; combined with the expanded network reachability, the change “potentially made the production servers reachable from a network accessible to thousands of VPN users,” the account says. After Brinkley’s demonstration, supervisors immediately reverted the firewall rule to its prior state.
What this means for technologists, procurement officials, and the public
- Technologists and security teams: This episode centers on a single operational decision — a firewall rule change tied to provisioning — that materially altered exposure. Teams will watch for ad hoc changes routed around the usual security reviewers and for shared third-party VPN arrangements that broaden trust boundaries.
- Procurement and contracting officials: The datacenter provided the VPN, not the government. That split in responsibility highlights the need to scrutinize how vendor-provided connectivity and multi-tenant hosting change access models for classified or otherwise sensitive systems.
- The general public: The servers described held about 50 million immigration records. Even when credentials are required, the account underlines how expanded network access combined with weak authentication can magnify risk to personally sensitive datasets.
The practical lesson Brinkley draws is concise and blunt: a VPN plus passwords is not sufficient for highly sensitive data. “It’s not enough to do the minimum,” the source concludes — and, in this case, the minimum was corrected only after a hands-on demonstration that made the risk plain.




