in

Inspector General Horowitz: Fed Can’t Explain 279 Security Alerts

The Federal Reserve’s own watchdog just handed the central bank a very public, very uncomfortable report card. The Board’s Office of Inspector General says a retiring staffer triggered 279 data‑loss‑prevention (DLP) alerts in the months before leaving, and the Fed still can’t say with confidence what sensitive material may have walked out the door. That isn’t a small clerical error. It is a glaring failure of basic information security and offboarding controls.

What the OIG discovered about the 279 DLP alerts

The Office of Inspector General, led by Inspector General Michael E. Horowitz, issued a management alert after auditing the Board’s offboarding process. The report centers on a 2024 case in the Division of International Finance where a departing employee set off 279 DLP alerts in roughly three months. About 40% of those alerts were flagged as potentially involving FOMC‑classified material — the kind of internal Fed documents that can move markets if mishandled.

The person involved had a prior history: the OIG report notes earlier incidents, including copying hundreds of FOMC‑classified files to an unencrypted USB device and an attempted transfer of Fed material to a personal email account. Many alerts clustered right before a planned trip to a country the Board considered restricted. The OIG referred the matter to its investigations office but said the Board’s recordkeeping and inconsistent follow‑up left investigators unable to determine conclusively what, if anything, was removed.

Why this matters: market sensitivity and insider risk

This isn’t just an IT problem. The Fed holds market‑sensitive information about monetary policy. If classified FOMC materials leak, traders and foreign actors could gain unfair advantages. The OIG did not accuse the employee of espionage or prove a leak. But the bigger finding is governance failure: the security system raised its hand 279 times, and human processes were not in place to answer.

OIG recommendations and the Board’s promised fixes

The management alert included nine recommendations to strengthen escalation, clarify roles, and ensure DLP alerts get resolved before an employee departs. The Board agreed to the changes and pledged to tighten controls on departing staff and removable media. Officials say fixes to alert escalation are expected by the first quarter of 2027. That timeline is something to watch — when your computer cries wolf 279 times, you don’t get the luxury of a slow rollout.

The lesson here is plain: software can only do so much. Data‑loss‑prevention tools can flag risky behavior, but they don’t close the loop. The Fed’s watchdog did the hard work of pointing out the gap. Now the Fed must show it can actually fix the human side of cybersecurity — timely escalation, consistent documentation, and real recovery steps when things go wrong. If 279 alerts can be left unresolved, the Board owes the public a clearer explanation and faster action. Otherwise we’re left with the worst kind of silence — not the absence of wrongdoing, but the absence of answers.

Written by Staff Reports

Fox Hires Melissa DeRosa, Sparks Outrage Over Nursing‑Home Cover-Up

Fox Hires Melissa DeRosa, Sparks Outrage Over Nursing‑Home Cover-Up