The inspector general urged the agency to secure equipment that may contain sensitive consumer, financial, and supervisory information. The agency disputed the assertion that data is at risk.

The Consumer Financial Protection Bureau (CFPB) has not verified whether hardware it left at four former regional offices is properly secured, according to a Sept. 30 management alert from the agency’s inspector general.

The Office of Inspector General (OIG) for the Federal Reserve Board and CFPB issued the alert publicly last week, but CFPB had responded to a draft of the alert on Sept. 18 and told the watchdog it planned to complete a site-by-site decommissioning of the offices by Sept. 30.

MeriTalk asked OIG whether CFPB met that deadline and completed the work. OIG declined to comment.

The alert indicated that OIG identified the issue during its ongoing 2026 Federal Information Security Modernization Act (FISMA) audit and issued the management alert ahead of its full report because it found a potential security risk requiring CFPB’s immediate attention.

CFPB officials told OIG that the agency left hardware at regional offices in Atlanta, Chicago, New York, and San Francisco that it vacated in 2025. The General Services Administration manages occupancy and lease administration responsibilities for those locations, but CFPB retained ownership of and responsibility for the IT assets left behind, according to the alert.

CFPB officials told the watchdog in June 2026 – and reconfirmed in September – that the agency “has not verified whether those hardware assets, which the agency remains accountable for, are appropriately secured.”

“As of September 2026, [CFPB] has no approved plan or time frame for verifying the security of hardware assets at former regional sites because of ongoing litigation and a lack of approvals to travel to these offices,” the alert said.

Federal agencies are required to control physical access at entry and exit points of facilities housing hardware and verify individuals’ authorization before granting access, the alert said. Federal guidance also calls for organizations to use asset-location technologies to track and monitor system components in controlled areas and detect unauthorized movement or removal.

CFPB maintains databases containing millions of consumer complaints, sensitive financial information, and confidential supervisory records on financial institutions, according to OIG.

“By not verifying the security of these assets, which were left in four former regional offices over 18 months ago, the CFPB has no way of knowing whether the hardware assets, or the sensitive data that may be stored on them, have been accessed, modified, or removed by unauthorized individuals,” OIG wrote.

CFPB disputed that characterization of the risk. In its response to the draft alert, the agency said OIG had mischaracterized the nature of the hardware at the regional offices. CFPB said it operates a centralized data center and uses cloud providers, while equipment at the former regional offices primarily supported infrastructure, network and internet access, administrative functions, and audiovisual needs.

The agency also said databases containing sensitive data were not housed at the regional offices and rejected OIG’s assertion that the hardware increased CFPB’s vulnerability to data breaches and unauthorized disclosure of sensitive or confidential information.

OIG recommended that CFPB ensure the hardware at the former regional offices is properly accounted for and secured.

CFPB concurred with the recommendation in its Sept. 18 response to OIG’s draft alert. The agency’s chief information officer, Christopher Chilbert, said “the CFPB has begun a full, site-by-site IT decommissioning of the former regional offices.”

“The CFPB plans to follow a standardized, documented process to decommission the offices by September 30, 2026, and provide [OIG] with an update once complete,” the alert reads.
OIG plans to provide additional information on the issue in its forthcoming 2026 CFPB FISMA report.

Read More About
About
Lisbeth Perez
Lisbeth Perez is a MeriTalk Senior Technology Reporter covering the intersection of government and technology.
Tags