TL;DR
Get smart everyday buys delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
The Federal Reserve’s Office of Inspector General issued a management alert over weaknesses in the Board’s handling of a 2024 information security incident involving a departing employee. The OIG said unclear responsibilities and limited follow-up left the matter unresolved for more than a year; the Board agreed with its recommendations and has set improvement milestones through 2027.
The Federal Reserve’s Office of Inspector General says weaknesses in the Board’s security controls and follow-up left a potential information removal incident involving a departing employee unresolved for more than a year. The watchdog issued a management alert before its planned audit was complete, citing risks that could affect how the central bank identifies and responds to sensitive information leaving its systems.
The alert concerns a former employee in the Board’s Division of International Finance who potentially removed classified Federal Open Market Committee material and other sensitive files while preparing to retire. The OIG said the employee announced plans to retire in February 2024 and expressed a desire to remove files. The incident began shortly before the employee traveled in June to a country the Board had designated as restricted, and continued after the employee retired in July. The division was unaware of the travel plans, according to the report.
The OIG learned of the potential 2024 incident in July 2025. It said many alerts about possible information removal were false positives and that evidence did not provide a sufficient basis to pursue a misconduct investigation. The watchdog said the incident nevertheless illustrated broader weaknesses in the Board’s offboarding process. It found the Board’s review of the incident insufficient, its policies for responding to information removal incidents inadequate, and escalation weaker than it should have been.
The report also describes earlier episodes involving the same employee. In 2021, the information security operations team alerted the division that the employee had copied files to an unencrypted USB device. The employee said they mistakenly believed the device was encrypted and was being used to back up files, the OIG reported. In 2023, the employee tried to send sensitive FOMC classified information to a personal email account; the division told the OIG the employee described that attempt as inadvertent. After counseling about transfers to USB devices, the employee engaged in similar activity before retiring in 2024 without seeking a supervisor’s review, according to the watchdog.
How the Fed Plans to Tighten Controls
The report raises questions about the Board’s ability to act when security alerts involve staff departures and potentially sensitive information. The OIG attributed the prolonged response to unclear ownership and conflicting views among groups about who was responsible for escalation and resolution. In the watchdog’s assessment, limited follow-up did not match the risks accumulating in the case.
The concern extends beyond this employee’s offboarding. The Board’s information security program depends on groups understanding who reviews alerts, when concerns move to higher levels, and who can close a case. The OIG warned that continued process weaknesses could undermine the program and increase the risk of a major breach. That is a risk assessment from the watchdog; the report does not say that a major breach occurred in this incident.
The Board concurred with the OIG’s recommendations. It plans to define roles and responsibilities and strengthen escalation processes by the first quarter of 2027. It also plans enhanced monitoring and escalation protocols through a new data loss prevention solution by the third quarter of 2027. Those deadlines give the Board time to make changes, while leaving the effectiveness of the planned controls to be assessed later.
Earlier Alerts Preceded Retirement
The OIG’s alert follows a series of reported information handling episodes over several years. The 2021 USB transfer and the 2023 attempt to send classified material to a personal email account had both come to the attention of the division, according to the report. The employee characterized those actions as mistakes, but the watchdog said similar activity occurred again before the 2024 retirement.
The report connects those past events to the Board’s handling of the later offboarding incident. The OIG said counseling had taken place after the USB episode, but the potential 2024 removal was not resolved promptly. The watchdog described responsibilities across multiple groups as unclear, with conflicting understandings of escalation contributing to the delay. It said clearer processes, defined roles and shared responsibility would help the Board respond appropriately.
The OIG issued its management alert while a planned audit was still underway because it believed the identified concerns required the Board’s attention before the audit was complete. The alert presents the watchdog’s interim concerns and recommendations; it does not establish that every possible removal alert represented an actual transfer of sensitive information.
“The failures involved a collective lack of action across multiple divisions, and the limited follow-up activities that did occur were not commensurate with the accumulation of risks in this situation.”
— Federal Reserve Office of Inspector General
What the Alert Does Not Establish
The report does not establish that the employee successfully removed all the information that triggered alerts. The OIG said many alerts were false positives and found insufficient grounds for a misconduct investigation of the 2024 offboarding incident. The possibility that sensitive information was removed remains part of the reported concern, rather than a confirmed finding of misconduct.
The source material also does not specify what information, if any, was ultimately outside the Board’s control, or whether it was accessed by anyone else. It does not describe a confirmed breach or disclose the full outcome of the ongoing planned audit. The Board’s agreement with the recommendations records its response, but the measures have not yet reached their stated implementation dates.
Board Changes Due Through 2027
The Board’s stated next steps are to set out roles and responsibilities and strengthen escalation processes by the first quarter of 2027. A later milestone, the planned data loss prevention solution with enhanced monitoring and escalation protocols, is scheduled for the third quarter of 2027.
The OIG’s planned audit is also relevant to what readers learn next. The alert was issued ahead of its completion, and the source material does not give a completion date. Further findings could clarify how the Board’s review and policies performed, while progress against the two implementation milestones will show whether the agreed changes have been put in place.
Key Questions
What did the Federal Reserve OIG report?
The OIG reported weaknesses in the Board’s response to a potential 2024 information removal incident involving a departing employee. It said unclear responsibilities and limited follow-up left the matter unresolved for more than a year.
Did the OIG find that the employee committed misconduct?
No misconduct finding is stated in the source material. The OIG said it lacked a sufficient basis to pursue a misconduct investigation of the 2024 incident, in part because many alerts were false positives.
What earlier incidents did the report describe?
The report says the employee copied files to an unencrypted USB device in 2021 and tried to send sensitive FOMC classified material to a personal email account in 2023. The employee described the actions as inadvertent, according to the OIG and the division’s account.
What changes has the Federal Reserve Board agreed to make?
The Board concurred with the recommendations. It plans clearer role and escalation processes by the first quarter of 2027, followed by enhanced monitoring and escalation protocols through a data loss prevention solution by the third quarter of 2027.
Source: rss
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
