A Federal Reserve employee triggered 279 data-loss-prevention alerts in the 90 days before retiring, including 111 involving information flagged as potentially FOMC-classified, yet weaknesses in the central bank’s own controls ultimately left investigators without enough evidence to open a misconduct investigation.
The finding comes from a management alert by the Federal Reserve Office of Inspector General examining how the Board handles departing employees and sensitive information.
Of the 279 alerts, 227 occurred in June 2024. Another 192 occurred three days before the employee traveled to a country the Fed classified as restricted, followed by a separate month-long international trip.
The employee’s International Finance division said it did not know the first destination was restricted.
The alerts involved printing, copying information into a notepad application, emailing potentially sensitive material to personal addresses, and transferring files to an unencrypted Fed-issued USB device. The employee had not obtained the required approval for removing information.
The history stretched back years. In 2021, the Fed confirmed that the same employee copied hundreds of FOMC-classified files to an unencrypted USB device. The employee said they mistakenly believed the device was encrypted.
In 2023, an attempt to email classified FOMC material to a personal account was blocked automatically. Later that year, another USB transfer generated alerts involving 83 files.
The OIG referred the 2024 matter to investigators in September 2025. They declined to pursue a misconduct investigation because available records did not clearly establish what information had actually been removed, while many alerts were confirmed as false positives.
The files eventually submitted by the former employee for review contained none of the material associated with the original alerts, while emails and printed documents were never recovered for review. The incident remained unresolved for more than a year.
The Fed agreed with the OIG’s recommendations and plans new escalation procedures by early 2027 and enhanced monitoring through a new data-loss-prevention system by Q3 2027.