A Federal Reserve inspector general alert raises a serious question about information security while drawing a clear limit around what is known. The watchdog found control failures in the Board's handling of a departing employee who may have removed sensitive material. It also said the evidence did not support a misconduct investigation.
The management alert is dated September 24 and drew wider attention when Reuters reported it Monday. It describes one employee who retired from the Board's Division of International Finance in July 2024. In the 90 days before retirement, the employee triggered 279 data-loss-prevention alerts, 111 of which the system marked as potentially involving sensitive Federal Open Market Committee information. The report says 40 more alerts were marked as potentially involving another restricted internal category. These are automated flags, not a verified count of stolen files.
What the records show
The alert describes activity that included printing, copying material to an unencrypted USB device and attempted transfers involving personal email addresses. It also describes earlier incidents involving the same employee, including a 2021 transfer of hundreds of FOMC-classified files to an unencrypted device. The employee said that earlier transfer reflected a mistaken belief that the device was encrypted, according to the report. The watchdog's concern was how the organization documented, escalated and resolved such events across divisions.
In June 2024, 227 of the 279 alerts occurred, with 192 falling three days before the employee traveled to a country the Board classified as restricted for device-security purposes. That timing appears in the inspector general's chronology, but it does not establish that information was taken abroad or given to anyone. The employee's division told investigators that some alerts were false positives. The report says managers did not always verify that explanation by examining the underlying files, leaving gaps in the record.
Why the watchdog stopped short
The inspector general referred the matter to its investigations office in September 2025. That office decided there was not enough basis to pursue misconduct, partly because records did not clearly show what information had been removed and partly because many alerts were confirmed as false positives. The public version of the report is also partly redacted. Those limitations are central facts, not footnotes: readers should not turn a possible incident into a proven leak, nor read the absence of a misconduct case as proof that every control worked.
The report uses the phrase FOMC-classified for the Federal Reserve's internal handling categories. It explicitly says the relevant information was not classified for national-security purposes. Confusing those systems would overstate the finding. The watchdog's point is operational: a central bank that holds potentially market-sensitive material needs a reliable way to know who accessed it, whether an attempted transfer succeeded and which team has responsibility to respond. In this case, the investigators say the available record could not answer every question.
What needs to change
The inspector general made nine recommendations to strengthen controls that prevent, detect and resolve potential removal of information. It issued the alert before finishing its planned audit because it considered the gaps urgent. A final report will assess broader offboarding processes, including records management and return or deactivation of credentials. This makes the present document a warning about a system, not a final verdict on one employee.
The next test is whether the Board implements measurable changes: clearer escalation rules, better handling of false alerts, records that preserve evidence, and checks before employees depart. A system that generates hundreds of warnings but cannot reliably distinguish harmless activity from genuine risk needs better follow-through. The case is newsworthy because it exposes that uncertainty at a powerful public institution. Its responsible reading is equally clear: the watchdog found weaknesses and unresolved questions, while explicitly declining to allege proven misconduct.
The sequence of dates helps explain the report's scope. The employee retired in 2024, the inspector general began its broader audit in 2025, and the public management alert arrived in September 2026. The delay does not by itself establish inaction throughout that period; the report documents review, referral and an eventual decision by investigators. It does mean the Board's response should be judged by evidence of corrected procedures, not by an immediate public accusation. The watchdog plans a separate final audit after more fieldwork. That later document can show whether the new rules address the specific gaps that made this case difficult to resolve.
Next checkpoint
What to watch
The Fed Board's responses to nine recommendations and the inspector general's later full offboarding audit.
Evidence
Sources and editorial notes
This is a document-led summary of a September 24 inspector general management alert reported more widely September 28. Potential removal is not presented as confirmed theft or a national-security classification breach.
- Federal Reserve Board OIG — management alert, September 24Primary document
- Reuters — watchdog alert reported September 28Original reporting
Spot an error? Read our corrections policy.



