An employee with the Federal Deposit Insurance Corporation (FDIC) reportedly took tens of thousands of banking records when she resigned her position in February, Federal Times has confirmed, though the agency said no information was compromised.
The leak — first reported by the Washington Post’s Joe Davidson on April 11 — occurred on Feb. 26. According to a FDIC spokesperson, the employee downloaded personal files and others she rightly had access to as part of her job to a thumb drive that she then took home. Three days later, on Feb. 29, information security officials were alerted to the bulk download and investigated.
The former employee was contacted and appeared to be contrite. She returned the thumb drive on March 1 and signed an affidavit attesting that no one else had seen or had access to its contents.
The drive included 44,000 records, mostly of contact information for customers of banks that had since closed.
“It is important to note that we used this technology, figured it out, got the information back and we reported it proactively to Congress out of an abundance of caution,” the spokesperson said.
“It is unusual and impressive that the FDIC was tracking sensitive data movements and was able to resolve the issue” so quickly, Dave Palmer, director of technology for Darktrace and a former member of the British MI5 and GCHQ, agreed. “Whether inadvertent or malicious, attacks are inevitable but internal immune systems that give visibility into anomalies combined with processes to respond results in good overall security.”
“How many other CISOs believe they would definitely have been able to identify and react to this error?” Palmer added.
The FDIC has since taken steps to improve its security posture, the agency spokesperson noted, including restricting employees’ ability to use removable hard drives.
“The vast majority of employees don’t have access to it any longer and we’re phasing it out for the rest,” the spokesperson said.




