The Federal Reserve's Office of Inspector General said weak coordination among several departments delayed the identification, reporting and resolution of a security incident involving a former employee who allegedly removed sensitive and confidential files. The case remained unresolved more than a year later.
The Fed plans to clarify departmental responsibilities and strengthen its process for escalating security alerts by the first quarter of 2027. The incident involved information belonging to the Federal Reserve Board and the Federal Open Market Committee, or FOMC, and has renewed questions about document controls during employee departures and the management of insider risk.
279 data-loss alerts in the 2024 case
In a report issued on September 28, the inspector general's office said the incident involved a former employee of the Division of International Finance. During the three months before the employee's retirement, the person triggered 279 data-loss prevention, or DLP, alerts. Of those, 111 were identified as potentially involving confidential FOMC information. The alerts occurred around the time of the employee's private travel to a restricted country.
The investigation found that the employee may have used unencrypted USB devices to remove hundreds of files containing sensitive and confidential information from the Federal Reserve Board and the FOMC. The report said the 2024 incident had not been fully resolved and that not all relevant material had been recovered.
The inspector general's office issued an early management alert after raising concerns about the Fed's handling of the matter before its scheduled audit had been completed.
Departments disagreed over escalation duties
The groups involved in reviewing the alerts included the information security operations team, the records management program, the Division of International Finance and the FOMC Secretariat. The inspector general's office said the circumstances may not have been properly documented or escalated through the chain of command.
The information security team understood its role to be limited to notifying the records management program. Staff in the FOMC Secretariat believed the legal department had already been informed, when it had not.
The report said the departments lacked a common understanding of who was responsible for escalating alerts and driving an incident to resolution. As a result, the response depended too heavily on the employee's home department. The inspector general's office identified the unclear division of responsibility as one reason the matter remained open for so long and said the Fed needs a consistent framework for managing insider risk.
Earlier document incidents in 2021 and 2023
The former employee had previously been associated with other document-security incidents. In 2021, the Division of International Finance learned that the employee had copied sensitive FOMC confidential files to an unencrypted USB device. The employee said the action had been accidental.
In 2023, the employee attempted to send sensitive FOMC information to a personal email account, but the transfer was unsuccessful.
The inspector general's office said prior suspected or confirmed violations, an impending departure and repeated international travel were all signals that should have been assessed together as part of an insider-risk review. The report did not conclude that every file had been transferred or disclosed without authorization, but said the departments failed to establish the facts promptly, making the incident more difficult to resolve.
Audit findings and corrective steps
The inspector general's 2025 audit covered every employee who left the Federal Reserve Board between January 1 and December 31, 2024, including interns. During the audit period, departing employees submitted 18 requests to remove information. The information security operations team separately notified the records management program of five cases that may have involved departing employees removing information.
The inspector general's office recommended stronger controls over incident handling to prevent employees from removing sensitive material without authorization when they leave the Fed. The central bank plans to implement revised procedures by the first quarter of 2027, define departmental roles and reinforce the escalation of security alerts.
The report is part of a series of recent reviews of the Fed's information management and internal controls. In June, the inspector general's office examined international-travel risk management. In July, it issued a report on preventing employees and officials from disclosing proprietary information and analysis.