US Consumer Financial Protection Bureau (CFPB) employees have reportedly transferred confidential records of approximately 256,000 consumers and confidential supervisory information from approximately 50 agencies to personal email accounts.
Congressman Bill Huizenga addressed the allegations in a letter dated April 18 to CFPB Director Rohit Chopra.
“At the time of your notice, you indicated that an investigation was ongoing. You explained.” “But many questions remain unanswered.”
Huizenga also asked Chopra to provide briefings to commission staff by April 25 to help “better understand mitigation and remediation efforts.”
Chris Hauk, Consumer Privacy Champion at Pixel Privacy, commented: “Hopefully the CFPB has canceled all access to that employee’s system.”
However, it’s unclear from the letter whether the CFPB conducted subsequent threat intelligence analysis to see if this data was appearing elsewhere, according to Specops senior product manager Darren James. .
You can read more about the data breach here: LastPass Breached: Password Managers in the spotlight
“CFPB has lessons to learn here in responsible data processing,” said James. “All the training that has been conducted has been unsuccessful and cyber-aware needs to place more emphasis on his training going forward to prevent such poor security hygiene.”
Comparitech’s privacy advocate Paul Bischoff agreed with James, saying it was “shamefully ironic” that the CFPB endangered consumer information.
“[Still], the breach was contained and no one’s information appears to be at risk. I think CFPB staff will be attending many meetings soon on how to properly handle data and workplace policies,” Bischoff concluded.
For more information on employee training, see this guide by Chrystal Taylor, Senior Technical Product Marketing Manager at SolarWinds.