Get 40% Off
⚠ Earnings Alert! Which stocks are poised to surge?
See the stocks on our ProPicks radar. These strategies gained 19.7% year-to-date.
Unlock full list

Congress subcommittee grills U.S. banks regulator about data breaches

Published 05/12/2016, 01:34 PM
Updated 05/12/2016, 01:40 PM
© Reuters. The Federal Deposit Insurance Corp (FDIC) logo is seen at the FDIC headquarters in Washington

WASHINGTON (Reuters) - Members of Congress on Thursday grilled the main U.S. banking regulator about a recent raft of data breaches, highlighting two incidents where workers downloaded more than 10,000 sensitive and private records onto portable storage devices before leaving the agency's employ.

After the Federal Deposit Insurance Corp uncovered those two breaches, it conducted a review and found five other instances when employees improperly stored and took personal information for tens of thousands of individuals, according to Representative Barry Loudermilk, a Republican who chairs a House of Representatives subcommittee on oversight and technology.

Altogether, more than 160,000 people were affected, Loudermilk said at a hearing covering the breaches.

"To date, FDIC has failed to notify any of those individuals that their private information may have been compromised," he added.

The highest-ranking Democrat on the subcommittee, Representative Don Beyer, said the concerns were shared by members of both parties and added the FDIC was too slow in notifying Congress about the breaks in data security. It should have informed lawmakers within seven days of the incidents, he said.

The FDIC's chief information officer and chief privacy officer, Lawrence Gross, told the hearing the agency is working to eliminate employees' use of portable media and has installed technology blocking most employees from downloading data from its systems to DVDs, CDs and flash drives.

It is also looking into "digital rights management" software limiting the time period someone can access information and putting up other barriers to redistributing information.

Gross, who started his role in November, said he is conducting a "top to bottom review" of the agency's information technology policies and planned to hire an independent third party to conduct an assessment.

The FDIC has said the downloads were inadvertent.

But members of Congress remained skeptical that the breaches were not intentional.

"In at least one case...a former employee who downloaded such data was evasive about her actions and not cooperative when initially confronted," said Representative Bill Johnson.

© Reuters. The Federal Deposit Insurance Corp (FDIC) logo is seen at the FDIC headquarters in Washington

"Some FDIC employees also suggest that it was highly improbable that this former employee's actions were accidental. In addition this former employee is now working for a U.S. subsidiary of a non-U.S. financial services company which raises additional concerns."

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.