Skip to content
TECH CEO Daily
FintechBreaking

Fed inspector general: retiring staffer set off 279 data alerts, case left open a year

A management alert describes a retiring research employee whose file transfers set off hundreds of alerts, and divisions that each assumed someone else would act.

By · Editor

· 4 min read · Fact-checked

The 60-second brief

  • 1A retiring Fed Board employee triggered 279 data-loss alerts in the 90 days before leaving in July 2024.
  • 2The inspector general said unclear roles across divisions left the possible incident unresolved for over a year.
  • 3The Board agreed to all nine recommendations, with most fixes, including a new data-loss tool, due by late 2027.

The news

The Fed inspector general said on September 24, 2026 that a Federal Reserve Board employee triggered 279 data-loss alerts before retiring in July 2024, some flagging possible Federal Open Market Committee (FOMC) files, and that the possible incident sat unresolved for over a year.

The findings come from a management alert by the Office of Inspector General (OIG) for the Board and the Consumer Financial Protection Bureau, issued partway through an audit of how the Board offboards departing staff. The OIG tested 26 cases of information removal by employees who left in 2024 and found gaps across multiple divisions. It chose this case, in the Division of International Finance, because it best showed the problems. Banking Dive reported on the alert on September 29.

According to the report, the employee announced plans in February 2024 to retire and said they wanted to take files with them, but never formally asked to do so. In the 90 days before leaving on July 2, 2024, the employee triggered 279 alerts from the Board's data loss prevention (DLP) software, which flags attempts to move sensitive files to places like personal email or USB drives. The software flagged 111 of the alerts as potentially involving FOMC classified information. The FOMC is the Fed body that sets interest rates.

The timing raised the OIG's concern. The report says 192 alerts came about three days before the employee left on a personal trip to a country the Board classifies as restricted, a trip the division did not know went to such a country. The employee had a history: in 2021 they copied hundreds of FOMC classified files to an unencrypted USB device, and in 2023 they tried to email FOMC information to a personal account, a message the Board's systems blocked.

After retirement, the employee returned a USB drive for review in August 2024. The OIG found it held none of the files that had triggered the alerts, and reviewers did not catch the gap. Follow-up on emailed and printed material stopped when the former employee did not respond. The OIG learned of the case during testing in July 2025 and said confusion over who was responsible contributed to it staying unresolved for more than a year.

The report stresses limits on what is known. The OIG referred the matter to its Office of Investigations in September 2025, which found insufficient basis for a misconduct investigation, partly because records did not show what was removed and many alerts proved to be false positives. The OIG also notes the Board's labels are internal and the information is not classified for national security purposes.

The numbers

Data-loss alerts in 90 days before retirement
279
Alerts flagged as potential FOMC classified information
111
Alerts about three days before trip to a restricted country
192
Removal cases the OIG tested
26
Recommendations, all accepted by the Board
9

Why CEOs should care

For CISOs at banks and fintechs, the report is a checklist of insider-risk failures that examiners regularly probe at supervised firms: no single owner for an alert, no escalation threshold, reviewers who checked the files an employee handed over instead of the files the alerts named, and a departing employee allowed to keep equipment past their last day. Ask your team who owns a DLP alert on a departing employee from start to finish, whether reviews compare returned files against the alert log, and whether unencrypted removable media is still allowed anywhere.

For CFOs and boards, the lesson is that insider controls cannot be left to the business unit where the employee sits. The OIG found each group assumed another would act. Offboarding for staff with access to market-moving or confidential data should include a lookback on their data activity, a hold on equipment returns until reviews finish, and a clear route to legal and security leadership.

For regulated firms preparing for exams, the report also shows the standard the Fed's watchdog applies to its own house. Expect supervisors to ask similar questions about departing-employee reviews and removable media, and document your answers before they do.

The bigger picture

The alert shows long-running gaps. The OIG says a 2019 recommendation to review DLP logs during offboarding and a 2024 recommendation to set a baseline process for reviewing DLP alerts both remain open. It also cites its June 2026 report urging broader foreign travel reporting for staff with access to FOMC or confidential supervisory information, and a July 2026 report calling for a more robust insider risk program.

The Board has already acted on part of the problem. In February 2026, the Division of IT began blocking any USB device from Board equipment until security staff add it to an approved list, the OIG reported.

What’s next

The Board concurred with all nine recommendations. It plans to define roles and escalation protocols by the first quarter of 2027 and deploy a new DLP system with enhanced monitoring by the third quarter of 2027; FOMC procedure updates are due by the fourth quarter of 2027. The OIG will resume its broader offboarding audit and issue a separate report.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Federal ReserveOffice of Inspector GeneralFOMCInsider risk

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.