ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

CFPB criticized for allegedly delaying response to a major insider theft incident

The Consumer Financial Protection Bureau in the United States is attracting strong criticism concerning how it responded to a recently-disclosed cybersecurity incident.CFPB, a US federal agency responsible for consumer protection in the financial sector, recently announced that it suffered a data breach after a former employee sent 14 emails containing confidential records to their personal email account.The former employee had access to the compromised information as a part of his job role, however, two of the files contained sensitive personal data like names and account numbers related to accounts belonging to a financial institution. CFPB has clarified that these details are used by the institution internally and cannot be used to access the accounts from outside.CFPB identified the security incident on February 21 and began notifying Congress on March 21. The agency said it directed the former employee to delete the stolen data and provide proof that it has been deleted, but hasn’t received any such evidence so far.The organisation is still working with financial institutions to understand the sensitivity of the leaked information. CFPB said that as of now it has no evidence of names being leaked but information like account numbers, loan numbers, income details, credit scores, and demographic information was leaked in the security incident.CFPB revoked the employee’s access to such data and fired him once the data leak was discovered. It has also notified Congress, the Cybersecurity and Infrastructure Security Agency, the Office of Management and Budget, and the Financial and Banking Information Infrastructure Committee about the security incident.According to the Cyber Wire, critics are unhappy with the way CFPB has been handling the cyber security incident. While the bureau said that its internal investigation is still ongoing, the fact that it waited for almost two months to disclose the data leak raised a lot of questions.Todd Zywicki, a law professor at George Mason University and senior fellow at the Cato Institute, told American Banker, “To sit on it for this long, and to withhold from both consumers and the affected firms that this happened and then simply dismiss it was anything important and don’t worry about it — it is hard to imagine the CFPB would be okay if some private company did that.”“Just like they expect companies to fully identify and remediate errors, they should do the same,” Lucy Morris, a partner at Hudson Cook and a former CFPB deputy enforcement director added.Bill Huizenga, the U.S. representative for Michigan’s 4th congressional district, also sent a letter to CFPB in which he wrote: “At the time of your notification, you indicated that the investigation was ongoing. You explained that the employee is no longer employed by the agency and that the employee certified they deleted each email. However, many questions remain unanswered.“To better understand the mitigation and remediation efforts, the scale of the breach, as well as efforts made to give the appropriate notifications, please provide a briefing to Committee staff as soon as possible but no later than April 25, 2023,”  Huizenga added.

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543