- Key takeaway: The Inspector General report found that gaps in coordination and unclear responsibilities among Fed divisions contributed to a sensitive information security incident that remained unresolved for more than a year.
- Expert quote: "The lack of clarity in each division's role in responding to this incident highlights the need for a consolidated program to manage insider risks at the Board." —Federal Reserve Office of the Inspector General report.
- What's at stake: The Fed said it plans to implement processes and protocols to clarify roles and strengthen the escalation of alerts by the first quarter of 2027.
WASHINGTON — The Federal Reserve has weaknesses in how its divisions coordinate to identify and resolve information security incidents, a government watchdog said.
The Fed's Office of Inspector General released a report Monday detailing an incident involving a former staffer in the Division of International Finance who potentially removed hundreds of documents containing sensitive and classified information from the board and the Federal Open Market Committee using an unencrypted USB device. The report raised concerns about how multiple Fed divisions responded to and handled the matter.
The case was examined as part of the OIG's 2025 audit of the board's controls for records management during employee offboarding.
"During our audit, we identified concerns with the response to an information security incident involving the potential removal of sensitive Board and FOMC classified information by a former IF employee," the OIG said in its report. "The 2024 incident was not fully resolved and the removed information was not fully retrieved."
According to the report, three months before retiring, the employee triggered 279 data loss prevention, or DLP, alerts. The DLP tool identified 111 of those alerts as potentially involving sensitive FOMC classified information. The alerts occurred shortly before the employee took a "personal trip to a restricted country," the report said.
For example, the information security team believed it could do nothing beyond alerting the Records Management Program, while FOMC Secretariat personnel believed the Legal Division had been informed. It had not.
"Each group's conflicting understanding of escalation and resolution responsibilities resulted in a general lack of clarity about how to proceed in addressing the incident and contributed to overreliance on the employee's division," the OIG said. "This lack of clarity contributed to the incident remaining unresolved for over a year."
The OIG said concerns about the board's handling of the incident prompted it to issue a management alert before completing its planned audit.
Read more:
OCC's Gould limiting examiner time at banks Another judge rejects Trump's attempt to halt CFPB funding How credit cards are playing into the Kansas Senate race Embattled California bank is latest to fail
Although the report focuses on the 2024 incident, the OIG noted that the same employee had attempted to export classified Fed documents in previous years.
In 2021, the Division of International Finance was notified that the employee had copied sensitive FOMC classified files to an unencrypted USB device. The employee said it was an accident, according to the report. Then, in 2023, the employee unsuccessfully attempted to send sensitive FOMC classified information to a personal email account.
"The employee's ongoing pattern of potential and confirmed security violations; the employee's imminent departure; and the presence of multiple insider threat risk indicators, including multiple international trips, signaled the possibility that a credible insider threat incident and potential material information security breach had occurred," the IG report said. "The lack of clarity in each division's role in responding to this incident highlights the need for a consolidated program to manage insider risks at the Board."
The government watchdog said the 2025 audit covered all employees, including interns, who departed the board between Jan. 1 and Dec. 31, 2024. During that period, departing employees submitted 18 information-removal requests, while the IS Operations team notified the Records Management Program of five potential cases involving the removal of information by departing employees.
Going forward, the Fed's inspector general recommends strengthening incident-handling controls to prevent future information security incidents involving the unauthorized removal of sensitive information by departing employees. The Fed said it plans to implement processes and protocols to clarify roles and strengthen the escalation of alerts by the first quarter of 2027.
The report is one of a series of reviews released by the Fed's inspector general in recent months. In July, the watchdog










