Full Report
A Federal Reserve Board staffer mishandled sensitive classified files and triggered hundreds of data loss prevention alerts leading up to their retirement, the agency’s inspector general revealed in a new report. The security issues with the employee were uncovered by the watchdog during its audit of the Fed’s offboarding process, which began in March 2025. Four…
Analysis Summary
# Incident Report: Insider Mishandling of Classified Federal Reserve Files
## Executive Summary
A Federal Reserve Board employee within the Division of International Finance repeatedly mishandled and attempted to remove sensitive classified files leading up to their retirement. The incident was characterized by the triggering of hundreds of Data Loss Prevention (DLP) alerts, which were subsequently identified during an Office of Inspector General (OIG) audit of the agency's offboarding procedures.
## Incident Details
- **Discovery Date:** July 2025 (During OIG audit review)
- **Incident Date:** Leading up to July 2024
- **Affected Organization:** Federal Reserve Board (Division of International Finance)
- **Sector:** Government / Financial Services
- **Geography:** Washington D.C., USA
## Timeline of Events
### Initial Access
- **Date/Time:** Pre-July 2024
- **Vector:** Authorized Insider Access
- **Details:** The subject was a legitimate staff member with authorized access to sensitive and classified systems as part of their job function.
### Lateral Movement
- **N/A:** The individual utilized existing credentials and legitimate access rights; no unauthorized lateral movement across the network was reported.
### Data Exfiltration/Impact
- **Date:** Leading up to July 2024 retirement.
- **Details:** The employee triggered hundreds of DLP alerts by attempting to move or remove sensitive classified files. The employee explicitly expressed a "desire to remove files" prior to their departure.
### Detection & Response
- **Detection:** The agency’s automated DLP systems triggered hundreds of alerts at the time of the activity. However, the full scope of the security failure was not fully realized until the OIG began an audit of the offboarding process in March 2025.
- **Response:** The OIG investigation led to a report published in late 2026 highlighting failures in the Fed’s offboarding and data protection oversight.
## Attack Methodology
- **Initial Access:** Authorized User Credentials.
- **Persistence:** Legitimate employment status.
- **Privilege Escalation:** None required; used existing permissions.
- **Defense Evasion:** Attempted to bypass or ignore internal data handling policies.
- **Credential Access:** Not applicable (Insider).
- **Discovery:** Internal file system navigation.
- **Lateral Movement:** None.
- **Collection:** Gathering sensitive classified files for personal removal.
- **Exfiltration:** Attempted physical or digital removal of files (thwarted or flagged by DLP).
- **Impact:** Compromise of information integrity and breach of classified document handling protocols.
## Impact Assessment
- **Financial:** Not disclosed; costs associated with OIG audit and remediation.
- **Data Breach:** Sensitive classified files; volume reached "hundreds" of alerts.
- **Operational:** Significant audit findings triggered a review of the entire agency's offboarding process.
- **Reputational:** High; raises concerns regarding the central bank’s ability to secure sensitive economic data from departing employees.
## Indicators of Compromise
- **Network indicators:** hxxps[://]oig[.]federalreserve[.]gov/reports/board-offboarding-process-sep2026[.]pdf
- **File indicators:** Multiple sensitive/classified filenames flagged by DLP.
- **Behavioral indicators:** Employee announcing retirement followed by a sharp increase in data transfer/access requests; verbal expression of intent to take files.
## Response Actions
- **Containment:** DLP alerts were triggered (though follow-up timing is questioned).
- **Eradication:** Audit of the employee's access and recovered files.
- **Recovery:** Revision of the Federal Reserve Board’s offboarding policies and improved monitoring of departing personnel.
## Lessons Learned
- **Key Takeaways:** Automated alerts (DLP) are ineffective if the organization lacks a robust, immediate response protocol for high-risk departing employees.
- **Process Gaps:** The offboarding process failed to effectively bridge the gap between "alert generation" and "management intervention" before the employee left the premises.
## Recommendations
- **Enhanced Offboarding:** Implement mandatory immediate-risk reviews for any employee in sensitive divisions who announces retirement or resignation.
- **DLP Integration:** Tighten DLP policies for "notice period" employees to block, rather than just alert, the transfer of classified files.
- **Human Factors:** Conduct exit interviews with a security officer present for all employees handling classified information.