Former CFPB employee sent data on 256,000 consumers to a personal email
- Organization
- Consumer Financial Protection Bureau
- Exploit
- Malicious Insider
- Industry
- Government Agency
The Consumer Financial Protection Bureau disclosed in April 2023 that a former employee had forwarded confidential supervisory and consumer information from agency systems to a personal email account.
The bureau said the employee, who was authorised to access the material, sent 14 emails containing personally identifiable information. Two spreadsheets listed names and transaction specific account numbers tied to roughly 256,000 consumer accounts at a single financial institution. The CFPB said those numbers were for internal use and could not be used to access customer accounts. Smaller data sets were also involved, and Roll Call reported that the 14 emails covered customers at seven financial institutions. The Record reported that the material included names, account numbers, loan numbers, income, credit scores and demographic information.
Accounts of the wider scope differed. Roll Call reported that a letter from Representative Bill Huizenga described roughly 65 emails and information potentially touching more than 50 financial institutions, a substantially larger figure than the bureau's own account.
The CFPB said it learned of the transfers in February 2023, with Roll Call giving the discovery date as 14 February and The Record placing it on or before 21 February, and notified Congress on 21 March. The agency revoked the employee's network access, ended their employment and referred the matter to its Office of Inspector General, calling the unauthorised transfer completely unacceptable.
As of the reporting date the former employee had not certified that the emails were deleted, and the bureau said it had no indication the data had travelled beyond the personal account.