Federal Reserve Employee's Data Mishandling Exposes Gaps in Sensitive Information Governance
A recent investigation by the Federal Reserve's inspector general uncovered a series of data mishandling incidents involving a retiring employee. The employee, who left in July 2024, triggered 279 data loss prevention alerts during their final 90 days of employment, including 111 that potentially involved sensitive FOMC material.
The report found that the employee copied hundreds of FOMC files to an unencrypted USB device in 2021 and attempted to send classified information to a personal email account in 2023. The Fed's IT team blocked this attempt, but data loss prevention alerts indicated that the employee may have copied 83 sensitive FOMC files to an unencrypted USB device later that year.
The inspector general found that the Federal Reserve did not properly review or escalate these incidents and that one 2024 incident was not fully resolved. The removed information was also not fully retrieved, highlighting gaps in the agency's data governance and management practices.