{"id":16270,"date":"2016-04-20T16:43:05","date_gmt":"2016-04-20T16:43:05","guid":{"rendered":"https:\/\/one.sightlinemg.com\/c4isrnet\/uncategorized\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/"},"modified":"2026-08-08T18:04:01","modified_gmt":"2026-08-08T18:04:01","slug":"fdic-waited-months-to-report-major-october-data-breach","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/","title":{"rendered":"FDIC waited months to report major October data breach"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Officials at the Federal Deposit Insurance Corporation were reportedly\u00a0aware of a major leak of personally identifiable information (PII) late last year but failed to inform Congress for several months, according to internal FDIC documents obtained by Federal Times.<\/p>\n\n\n\n<p>In October 2015, a FDIC employee left the agency for a job in the private sector and took with her thousands of records containing highly sensitive information, including <span class=\"rte rte-comment\">Social Security numbers, and <\/span>loan and banking information for American citizens,\u00a0according to a Feb. 19 report from FDIC Assistant Inspector General for Audits Mark Mulholland.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An investigation showed the former employee downloaded files onto a personal portable hard drive on Sept. 16 and 17, and Oct. 15, including &#8220;Suspicious Activity Reports, Bank Currency Transaction Reports, [Bank Secrecy Act] Customer Data Reports and a small subset of personal work and tax files,&#8221; the report stated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Among those files were some 10,000 Social Security numbers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The exfiltration was discovered on Oct. 23 and referred to FDIC&#8217;s Computer Security Incident Response Team and later the Data Breach Management Team, which investigated the incident further, according to the IG report. DBMT classified the incident as a breach on Nov. 25 and, on Dec. 2, determined that a large number of Social Security numbers has been compromised.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The FDIC reached out to the former employee&#8217;s lawyer on Dec. 2 requesting the portable drive be returned no later than Dec. 8, which it was.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After a series of internal meetings, CIO Larry Gross and FDIC leadership reportedly decided the incident did not constitute a &#8220;major&#8221; breach as defined by the Office of Management and Budget and therefore was not required to be reported.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During the IG&#8217;s investigation, Mulholland found the October incident did meet the threshold for a &#8220;major&#8221; designation and urged the CIO to report it to Congress by Dec. 9. He pointed to a stipulation under Federal Information Security Management Act that requires agencies to report such incidents to Congress within seven days after being labeled &#8220;major&#8221; and <a href=\"https:\/\/www.whitehouse.gov\/sites\/default\/files\/omb\/memoranda\/2016\/m-16-03.pdf\">OMB memo M-16-03<\/a>, which outlines this process in detail.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The OMB memo defines a &#8220;major&#8221; incident as one that involves classified or controlled unclassified information, is not easily recoverable, has a significant impact on the agency&#8217;s mission or meets a certain threshold based on the number or importance of records exfiltrated. The memo includes a decision matrix to help officials determine whether this definition applies in specific instances.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;In our view, the incident should now be reported immediately,&#8221; Mulholland wrote in the report.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gross, who <a href=\"http:\/\/www.federaltimes.com\/story\/government\/it\/cio\/2015\/10\/14\/fdic-cio\/73877516\/\">stepped into the CIO role<\/a> shortly after the incident occurred, agreed with the &#8220;breach&#8221; designation but &#8220;made a determination on behalf of the FDIC that the incident was not major,&#8221; according to the IG report.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CIO offered four reasons for rejecting the &#8220;major&#8221; designation:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The employee was not disgruntled when she left the FDIC.<\/li><li>A belief that the employee accidentally downloaded the information when attempting to download personal information because the employee was not familiar with information technology.<\/li><li>The employee was working through significant personal issues, including a divorce and not living at her residence, presenting a distraction for the employee.<\/li><li>The FDIC ultimately recovered the USB drive from the employee.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The IG disagreed with this assessment, stating that the incident met three of the four factors OMB set forth for considering whether a security event should be reported. Mulholland went on to note the OMB guidance does not consider things like whether the employee was disgruntled.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OMB officials, &#8220;when provided hypothetical mitigating factors such as those the CIO referenced earlier \u2026 advised us that such factors would not be an appropriate basis for determining an incident is not major and does not require reporting to Congress.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, the IG offered five reasons why the incident should have been reported:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The information was stored on a personal device, in an unencrypted format and without password protection. As a result, the information was accessible to anyone with access to the device. Further, the information was outside of the FDIC\u2019s control for almost two months and no technical means exists to obtain assurance that the information was not accessed by others.<\/li><li>The employee\u2019s new employer is a financial services firm owned by a parent company that is based in Bangalore, India.<\/li><li>The employee was not forthright with the FDIC when attempts were made to recover the information. For example, the employee repeatedly denied downloading the information and owning a portable storage device.<\/li><li>In November 2015, the employee\u2019s former supervisor expressed concern about the content of the files downloaded by the employee and the fact that many of the files were downloaded on the employee\u2019s last day of employment, which the supervisor believed may have indicated suspicious activity.<\/li><li>An employee who inappropriately copies information that he\/she knows \u2014\u00a0or should know \u2014\u00a0to be highly sensitive at the end of his\/her employment and who is at the same time dealing with major personal issues \u2014\u00a0e.g., a divorce, living in a hotel room, seeking employment \u2014\u00a0presents a heightened security risk profile.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The IG said the incident should have been reported to Congress by Dec. 9 \u2014\u00a0a week after it was discovered that Social Security numbers were included in the breach \u2014\u00a0or even earlier, on Nov. 6, based on initial investigations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As of the issuance of the IG report, FDIC investigators have yet to decide whether to offer credit monitoring services or even whether to inform those affected by the October incident. This pace is far too slow, in Mulholland&#8217;s assessment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Six weeks elapsed between the initial reporting of the incident and a determination of whether a breach had occurred and whether it required reporting,&#8221; he wrote. &#8220;Additional decisions regarding notification to individuals and\/or organizations impacted remain outstanding \u2014\u00a0almost four months after the incident became known.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An FDIC spokesperson told Federal Times that Gross ultimately concurred with the IG&#8217;s recommendation and reported the incident on Feb. 26.\u00a0As of this posting, it was unclear whether individuals whose Social Security numbers were exposed have been notified of the incident.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This wouldn&#8217;t be the last time an employee left the FDIC with sensitive information. On April 11, the Washington Post reported another similar breach in which <a href=\"http:\/\/www.federaltimes.com\/story\/government\/cybersecurity\/2016\/04\/11\/fdic-records-leak\/82903238\/\">a former employee left the FDIC with some 44,000 records<\/a>. A FDIC spokesperson told Federal Times there didn&#8217;t appear to be any malicious intent behind this incident and that the data was quickly returned and the offending former employee signed an affidavit attesting that no one else had seen or taken possession of the information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But this incident is different, as the exfiltrated information spent far more time outside FDIC networks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Our most significant and immediate concern, however, is that the FDIC needs to immediately report what we have concluded is a major incident to the appropriate Congressional committees,&#8221; Mulholland wrote. &#8220;The information involved in the incident includes a large volume of highly-sensitive PII, which increases the risk of identity theft and consumer fraud for the affected individuals.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to an inspector general investigation, the FDIC CIO failed to report a significant cybersecurity incident for months after incorrectly labeling it a minor event.<\/p>\n","protected":false},"author":7,"featured_media":45977,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":10,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":{"8":{"categories":["management"],"primary_category":"management"}}},"categories":[10],"tags":[],"coauthors":[2464],"class_list":["post-16270","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber"],"acf":{"subheadline":"","legacy_arc_id":"IV2BCHSEDBGNBCO3GX5B6ZV5QM","arc_canonical_url":"\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>FDIC waited months to report major October data breach - C4ISRNet<\/title>\n<meta name=\"description\" content=\"According to an inspector general investigation, the FDIC CIO failed to report a significant cybersecurity incident for months after incorrectly labeling it a minor event.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FDIC waited months to report major October data breach\" \/>\n<meta property=\"og:description\" content=\"According to an inspector general investigation, the FDIC CIO failed to report a significant cybersecurity incident for months after incorrectly labeling it a minor event.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/\" \/>\n<meta property=\"og:site_name\" content=\"C4ISRNet\" \/>\n<meta property=\"article:published_time\" content=\"2016-04-20T16:43:05+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T18:04:01+00:00\" \/>\n<meta name=\"author\" content=\"Aaron Boyd\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Aaron Boyd\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"FDIC waited months to report major October data breach\",\n\t            \"datePublished\": \"2016-04-20T16:43:05+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:04:01+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/\"\n\t            },\n\t            \"wordCount\": 1160,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635966750274003374-fed-thumb-drivejpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Cyber\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/\",\n\t            \"name\": \"FDIC waited months to report major October data breach - C4ISRNet\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635966750274003374-fed-thumb-drivejpg.jpg\",\n\t            \"datePublished\": \"2016-04-20T16:43:05+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:04:01+00:00\",\n\t            \"description\": \"According to an inspector general investigation, the FDIC CIO failed to report a significant cybersecurity incident for months after incorrectly labeling it a minor event.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635966750274003374-fed-thumb-drivejpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635966750274003374-fed-thumb-drivejpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2016\\\/04\\\/20\\\/fdic-waited-months-to-report-major-october-data-breach\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Cyber\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/\",\n\t                    \"ad_zone\": \"cyber\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"FDIC waited months to report major October data breach\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"description\": \"Media for the Intelligence-Age Military | C4ISRNET\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"caption\": \"C4ISRNet\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"FDIC waited months to report major October data breach - C4ISRNet","description":"According to an inspector general investigation, the FDIC CIO failed to report a significant cybersecurity incident for months after incorrectly labeling it a minor event.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/","og_locale":"en_US","og_type":"article","og_title":"FDIC waited months to report major October data breach","og_description":"According to an inspector general investigation, the FDIC CIO failed to report a significant cybersecurity incident for months after incorrectly labeling it a minor event.","og_url":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/","og_site_name":"C4ISRNet","article_published_time":"2016-04-20T16:43:05+00:00","article_modified_time":"2026-08-08T18:04:01+00:00","author":"Aaron Boyd","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Aaron Boyd","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"FDIC waited months to report major October data breach","datePublished":"2016-04-20T16:43:05+00:00","dateModified":"2026-08-08T18:04:01+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/"},"wordCount":1160,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635966750274003374-fed-thumb-drivejpg.jpg","articleSection":["Cyber"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/","name":"FDIC waited months to report major October data breach - C4ISRNet","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635966750274003374-fed-thumb-drivejpg.jpg","datePublished":"2016-04-20T16:43:05+00:00","dateModified":"2026-08-08T18:04:01+00:00","description":"According to an inspector general investigation, the FDIC CIO failed to report a significant cybersecurity incident for months after incorrectly labeling it a minor event.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635966750274003374-fed-thumb-drivejpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635966750274003374-fed-thumb-drivejpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2016\/04\/20\/fdic-waited-months-to-report-major-october-data-breach\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Cyber","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/","ad_zone":"cyber"},{"@type":"ListItem","position":3,"name":"FDIC waited months to report major October data breach"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","name":"C4ISRNet","description":"Media for the Intelligence-Age Military | C4ISRNET","publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/c4isrnet\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization","name":"C4ISRNet","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","caption":"C4ISRNet"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/c4isrnet\/author\/migration\/"}]}},"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635966750274003374-fed-thumb-drivejpg.jpg","jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"C4ISRNet","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/c4isrnet","push-errors":false,"_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/16270","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/comments?post=16270"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/16270\/revisions"}],"predecessor-version":[{"id":16285,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/16270\/revisions\/16285"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/media?parent=16270"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/categories?post=16270"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/tags?post=16270"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/coauthors?post=16270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}