A Federal Reserve employee transferred potentially sensitive files outside the central bank just before retiring, exposing gaps in the Fed's efforts to keep confidential information secret, according to a report from the central bank's inspector general's office.
The security lapse, which took place in 2024, included the removal of files flagged as potentially sensitive and related to the Fed's monetary-policy work. Access to policymakers' deliberations is tightly controlled.
The severity of the incident was uncovered by an audit from the Fed's internal watchdog office, which published a report about the incident Thursday. The audit's findings didn't support an investigation into misconduct by the retiring employee, in part because records didn't clearly show what the employee had taken, the inspector general's office said.
The report made nine recommendations for improving security measures, all of which the Fed agreed to and said it would work to implement.
"We concur with the OIG's recommendations to strengthen the Board's governance of its information security program and enforcement of its controls," senior Fed leaders wrote in a letter this month to the inspector-general official who oversaw the audit. "The Board takes these matters seriously and we plan to promptly take all required steps to implement all recommendations."
A Fed spokesman declined to comment.
Keeping confidential policy information secure is a high-stakes mission for the Fed. Bets placed by traders on the central bank's coming interest-rate decisions back futures contracts worth trillions.
Foreign spying is another threat. Earlier this year, a former Fed staff member, John Rogers, was sentenced to more than three years in prison for lying to investigators about sharing restricted Fed information with Chinese operatives.
The newly uncovered lapse took place in 2024 when a longtime researcher in the Fed's international-finance division, who hasn't been identified, was retiring.
During the staffer's final weeks on the job, the person put potentially sensitive files on an unencrypted USB drive and sent others to personal email addresses, days before traveling to a restricted country. Many of the file transfers possibly included confidential material about the work of the Federal Open Market Committee, the group of Fed officials who vote on interest rates, according to the audit report.
The Fed's security systems flagged the retiring researcher's actions. But when the Fed followed up, staffers failed to recover the files, according to the report.
Comments