Data Breaches Neutral 5

Fed insider made 3 attempts to exfiltrate FOMC files via USB

The Fed's inspector general flagged a retiring International Finance staffer for three attempts to move confidential FOMC files through unencrypted USB drives and personal email. Although no data removal was confirmed, the case exposes systemic offboarding and insider-threat gaps at the central bank.

· 5 min read · Verified by 2 sources ·

Beat this week

Last 7 days · Data Breaches

9 stories
7.2 avg impact
0% positive
89% negative
vs prior 7 days +3 +3 stories vs prior 7 days

Impact 7.2/10 (-0.8 vs prior). Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 89 percentage points.

  • 11% neutral
  • 89% negative

This story sits in Data Breaches — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Cybersecurity briefing

Key takeaways

5 impact
Neutralsentiment
2sources
5min read
  1. The Fed's inspector general flagged a retiring International Finance staffer for three attempts to move confidential FOMC files through unencrypted USB drives and personal email.
  2. Although no data removal was confirmed, the case exposes systemic offboarding and insider-threat gaps at the central bank.
Drawn from
  • wtvbam.com
  • whtc.com

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1The employee was first flagged in 2021 for copying confidential FOMC files to an unencrypted USB drive; the employee said it was a mistake.
  2. 2In 2023, the employee attempted to email confidential FOMC files to a personal address, later describing the action as inadvertent.
  3. 3In 2023, the employee was again flagged for copying classified files to an unencrypted USB drive without approval.
  4. 4The employee retired from the Federal Reserve in July 2024; the IG became aware of the issues in July 2025.
  5. 5The IG said available records did not provide a clear indication of what information was removed and many alerts were false positives.
  6. 6The IG called for the Fed Board's immediate attention and corrective action on offboarding processes for employees with access to confidential policymaking information.

Who's Affected

Federal Reserve Board of Governors
government agencyNegative
Federal Reserve Office of Inspector General
oversight bodyNeutral
Unnamed retiring employee
personNegative
FOMC confidential files
information assetNegative

Analysis

For security teams, the Federal Reserve report is a textbook insider-threat timeline: an employee with privileged FOMC access triggered three data-loss-prevention alerts over two years—an unencrypted USB copy in 2021, a personal-email attempt in 2023, and a second USB copy later that year—yet still retired normally in July 2024. The IG’s admission that many alerts were false positives and that records couldn’t show what was removed highlights the hard reality of alert fatigue and forensic blind spots in high-stakes environments.

The Federal Reserve’s Office of Inspector General has put the central bank on notice over a potential insider-data incident that never became a formal misconduct case but exposes gaps in how the Fed handles employees leaving with access to confidential policymaking material. In a report dated September 28, 2026, the IG described a retiring staff member in the Division of International Finance who was flagged on at least three separate occasions between 2021 and 2023 for attempting to move confidential Federal Open Market Committee files to unauthorized destinations. Those attempts included copying FOMC files to an unencrypted USB drive in 2021, emailing files to a personal address in 2023, and copying classified files to another unencrypted USB drive later in 2023. The employee, who retired in July 2024, claimed the 2021 action was a mistake and the 2023 email was “inadvertent.” The IG reported that available records did not provide a clear indication of what information the employee had removed, and many of the alerts tied to the case were false positives.

The Division of International Finance sits at the intersection of U.S.

That combination—a repeated pattern of flags, an employee who still exited normally, and an incomplete forensic picture—is precisely why the IG elevated the matter beyond a single personnel problem. The report states the specific details “help to illustrate the systemic concerns” about the Fed’s offboarding process for employees with access to confidential policymaking information. Those breakdowns, the IG said, require “the Board’s immediate attention so that it can take appropriate corrective actions.” The central bank’s Board of Governors did not immediately respond to a request for comment, and the IG declined to identify the employee.

The Division of International Finance sits at the intersection of U.S. monetary policy and global economic conditions. Its staff routinely handle FOMC briefing materials, economic projections, exchange-rate analysis, and policy scenarios before they become public. Unauthorized removal of those records is not merely a bureaucratic infraction; it is a potential market-integrity event. Pre-decisional macro information can carry a trading advantage, and the Fed has long operated under strict protocols to limit who sees what before scheduled releases. The IG’s finding that a departing employee attempted multiple exfiltration routes—removable media and personal email—without approval, despite prior guidance on offboarding information, raises questions about whether those protocols are enforced consistently at the point of greatest insider-threat risk: the moment an employee disengages.

From a cybersecurity perspective, the case reads like a classic insider-threat trajectory. Detection systems fired in 2021 and 2023, but the organization apparently lacked the investigative or disciplinary follow-through to establish what was taken. False positives complicated the picture, and the IG notes records were insufficient. That creates a particularly frustrating situation for security and compliance teams: alerts that may be too noisy to act on individually can still represent a pattern that only becomes visible in hindsight. Unencrypted USB drives remain a serious vector because they can be lost, copied, or re-read elsewhere without leaving the same audit trail as network transfers. The fact that an employee attempted personal-email exfiltration after previously being caught copying to USB indicates either a repeated misunderstanding of policy or a disregard for it, and the IG’s warning to the Board suggests the latter possibility was not ruled out.

What to Watch

For financial market participants, the immediate market impact is likely minimal because there is no confirmation that specific information actually left the Fed or was used in trading. The IG explicitly said records did not provide a clear indication of what was removed, and many alerts were false positives. However, the report is a red flag for governance rather than a clean bill of health. If the Fed cannot determine what a departing International Finance staffer removed over a multi-year period, then market participants must weigh the tail risk that some pre-decisional policy information may have escaped the central bank’s perimeter. That is the kind of ambiguity that can attract congressional interest and prompt reviews by other financial regulators, even if no enforcement action follows.

Looking ahead, the Board is now under pressure to demonstrate it treats offboarding as a security-critical process, not an HR formality. Likely corrective actions include tighter controls on USB and personal-email activity, longer retention of departure logs and endpoint telemetry, clearer thresholds for when repeated flags trigger formal investigations, and perhaps a reclassification of certain FOMC materials as formal misconduct triggers. For the cybersecurity community, the incident will become a reference case for why false positives must not be allowed to drown out persistent insider indicators. For the finance community, it is a reminder that the Federal Reserve’s legitimacy rests not only on its policy decisions but also on its ability to keep pre-decisional information confidential. If subsequent reporting identifies the employee or finds that specific materials were removed, this story could escalate from a controls problem into a market-integrity event.

Timeline

Timeline

  1. First exfiltration alert

  2. Personal email attempt

  3. Second USB flag

  4. Employee retires

  5. IG becomes aware

  6. IG report released

Source cluster

Primary reporting

2articles

Cite This Page

"Fed insider made 3 attempts to exfiltrate FOMC files via USB." Cyber Intelligence Brief, September 28, 2026. https://getcyberbrief.com/story/fed-insider-3-exfiltration-attempts-fomc-files

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.