US Federal News Bureau

Federal Reserve Data Mishandling Exposes Gaps in Sensitive Information Governance

avatar

Written by: Tathagata Sen

Updated 1:15 AM EDT, October 2, 2026

post detail image

Photo credit: Unsplash.com

A Federal Reserve Board employee repeatedly removed sensitive files before retiring in July 2024, triggering hundreds of data loss prevention alerts, according to a September 24 report by the agency’s inspector general. 

According to an October 1 FedScoop report, the employee copied files to an unencrypted USB device, attempted to send classified Federal Open Market Committee (FOMC) information to a personal email account and moved other sensitive information outside approved systems.

The inspector general found that the Federal Reserve did not respond adequately to the incidents. Its review found that the employee triggered 279 data loss prevention alerts during the final 90 days of employment, including 111 that potentially involved sensitive FOMC material. The watchdog said the Fed’s controls, incident response procedures and standards for departing employees were not clear or consistent.

Data Controls Failed to Keep Pace With the Risk

According to the report, the incidents stretched back several years. 

In 2021, the employee copied hundreds of FOMC files to an unencrypted USB device. In 2023, the employee tried to send classified FOMC information to a personal email account, which the Fed’s IT team blocked. Later that year, data loss prevention alerts indicated that the employee may have copied 83 sensitive FOMC files to an unencrypted USB device.

The inspector general said the Fed did not properly review or escalate the incidents. It also found that one 2024 incident was not fully resolved and that the removed information was not fully retrieved. The Federal Reserve agreed with all nine recommendations in the report.

Sensitive Data Needs Stronger Lifecycle Controls

For chief data officers (CDOs), the findings show why data governance has to cover the full lifecycle of sensitive information, including when employees leave an organization. CDOs need visibility into who can access sensitive data, how that data can be moved and whether controls can detect and stop unauthorized transfers.

The case also shows why alerts alone are not enough. Organizations need clear rules for reviewing alerts, escalating incidents and removing access as employees approach departure. Those processes help ensure that sensitive information remains protected even when data is handled across different systems and teams.



Related Stories

Similar Topics
Artificial Intelligence
Data Management
Diversity
Testimonials
background imagebackground image
Community Network

Join Our Community

starElevate Your Personal Brand

starShape the Data Leadership Agenda

starBuild a Lasting Network

starExchange Knowledge & Experience

starStay Updated & Future-Ready

logo
Social media icon
Social media icon
Social media icon
Social media icon
About