CFPB Fails Its Own Data Security Test
The Consumer Financial Protection Bureau has spent years warning financial companies that protecting consumers’ personal and financial information isn’t optional. Now, the federal agency responsible for enforcing many of those protections is facing a data-security warning from its own watchdog.
On September 30, the Office of Inspector General for the Federal Reserve Board and CFPB issued a management alert after discovering that the CFPB had left hardware assets at former regional offices it vacated and had not verified whether those assets were properly secured. The OIG warned that CFPB data, if exposed, could reveal private information belonging to consumers and businesses, undermine public trust and compromise enforcement of consumer financial laws.
The CFPB pushed back on one important part of the concern. Chief Information Officer Christopher Chilbert told the OIG that the bureau uses a centralized data center and cloud providers and that the equipment left at the regional offices does not contain databases holding sensitive information. He said the OIG had no basis for concluding that the hardware increased the vulnerability of CFPB data to a breach. Nevertheless, the CFPB agreed with the recommendation and began removing the equipment.
Here’s where the situation gets interesting.
In 2022, the CFPB issued its own guidance stating that inadequate security for sensitive consumer information can constitute an unfair practice under the Consumer Financial Protection Act. The bureau specifically said inadequate data security can be an unfair practice even when there has been no breach or intrusion. The CFPB explained that a significant risk of harm can be enough because consumers generally cannot see or control how a company protects their information.
In other words, the CFPB’s own position has been that companies shouldn’t have to wait for somebody’s financial information to actually be stolen before inadequate security becomes a problem.
That makes the OIG’s latest finding difficult to ignore.
The watchdog didn’t say the CFPB suffered a data breach. It didn’t say sensitive consumer information was stolen. And it did not conclude that the CFPB violated a specific regulation.
What it did say was that the bureau left hardware at former regional offices and had not verified that the equipment was properly secured.
And this isn’t the first time the OIG has raised concerns about the CFPB’s handling of IT equipment.
In November 2025, the OIG reported that the CFPB maintained a large inventory of aging, unassigned IT assets and had not established effective processes for managing their storage or reducing the inventory. The watchdog warned that better management was necessary to limit the risk of loss or theft and protect agency data.
The OIG’s audit history also shows that the CFPB’s information-security program had deteriorated. The watchdog reported that the program’s maturity dropped from Level 4, described as “managed and measurable,” to Level 2, “defined,” during fiscal year 2025, leading the OIG to conclude that the program was no longer effective.
So the issue isn’t simply a few computers sitting in an empty office.
It is a federal regulator that has told financial companies that inadequate data security can create legal liability based on the risk of harm, while its own inspector general has repeatedly identified weaknesses involving the agency’s information-security program and physical IT assets.
The CFPB says the equipment left behind did not contain its sensitive databases and is now being removed. The OIG says it will follow up to determine whether the recommendation has been fully addressed.












