CFPB Clears Hardware From Vacated Offices After Watchdog Security Warning

CFPB

A government watchdog issued a report Wednesday (Sept. 30) saying that it had recommended that the Consumer Financial Protection Bureau (CFPB) secure hardware assets that it left at former regional offices it vacated in early 2025.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The watchdog, the Office of Inspector General for the Board of Governors of the Federal Reserve System and the Consumer Financial Protection Bureau (OIG), said in a summary of the report that it discovered during an ongoing audit that the CFPB had left the hardware at the former offices and had not verified whether the assets were properly secured.

    The CFPB maintains databases that include consumer complaints, financial information and confidential supervisory records on financial institutions, and some of that information may reside on the regulator’s hardware assets, the OIG said in its report.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    Because it found a potential security risk involving the CFPB’s hardware assets during its audit, and determined that it required the CFPB’s immediate attention, the OIG issued a draft management alert ahead of its full report.

    In a CFPB response to the OIG’s recommendation, which was dated Sept. 18 and included in OIG’s report, CFPB Chief Information Officer Christopher Chilbert said that the regulator agrees with the OIG’s recommendation and had already begun removing physical assets from the former offices.

    Chilbert added that because the CFPB has a centralized data center and uses cloud providers, the assets in the regional offices do not contain databases with sensitive information. Chilbert said that the OIG has no basis for its assertion that the hardware increases vulnerability to data breaches.

    “Nonetheless, as noted above, we are in the process of implementing the recommendation,” Chilbert said in the Sept. 18 response.

    The OIG said in its report that the CFPB concurred with its recommendation, that the regulator planned to complete its decommissioning of the former regional offices by Sept. 30, and that it would provide the OIG with an update when finished.

    “The actions described by the CFPB appear to be responsive to our recommendation,” the OIG said in the report. “We will follow up to ensure that the recommendation is fully addressed.”

    Bloomberg Law reported Monday (Sept. 28) that the Trump administration has been attempting to withhold funding from the CFPB and that a recent court ruling blocked one of those attempts.