Full Breakdown
Federal Reserve Inspector General Flags Potential Data Exfiltration by Retiring Employee
By Drooid · · How we work
Core Incident and Findings
The Federal Reserve’s Office of the Inspector General (IG) reported that a staff member from the Division of International Finance, who retired in July 2024, was repeatedly caught attempting to remove confidential information as the employee exited the agency. The IG concluded that the available records did not clearly show what data, if any, was taken and that many of the alerts were “false positives.” Consequently, the IG determined there was insufficient basis to open a formal misconduct investigation.
Timeline of Alerts
- 2021: The employee was first flagged for copying Federal Open Market Committee (FOMC) files to an unencrypted USB drive; the employee later claimed the action was accidental.
- 2023: Two separate incidents occurred—an attempt to email confidential FOMC files to a personal address and another instance of copying classified files to an unencrypted USB drive. Both were described by the employee as inadvertent.
- July 2025: The IG became aware of the series of alerts as the employee prepared for a personal trip to a restricted country, followed by a month-long international trip.
- September 28 2026: The IG released its report, noting that the employee generated additional alerts for printing, copying data to a notepad application, emailing sensitive information to multiple personal addresses, and transferring files to a Board-issued unencrypted USB device.
Systemic Concerns and Official Response
The IG highlighted “systemic concerns” about the Fed’s off-boarding procedures for staff with access to confidential policymaking information. While the Board of Governors did not immediately comment, the IG urged the Board to take “immediate attention” and implement corrective actions to strengthen exit protocols and data-handling safeguards.
Potential Impact on Federal Reserve Security Practices
The episode underscores vulnerabilities in the Fed’s information-security controls, especially regarding unencrypted storage devices and personal email use. If unaddressed, similar lapses could expose sensitive monetary-policy deliberations, potentially affecting market confidence and the integrity of the central bank’s decision-making process.
Next Steps
The IG’s report recommends a review of off-boarding policies, enhanced monitoring of data transfers during international travel, and stricter enforcement of encryption requirements for any portable media. The Board is expected to consider these recommendations in upcoming internal governance meetings.
