The Consumer Financial Protection Bureau's (CFPB) information security program was downgraded from a level 4 ("managed and measurable") to a level 2 ("defined") maturity rating following an audit by the Federal Reserve's Office of the Inspector General (OIG). The audit cited the agency's failure to maintain system authorizations and the absence of comprehensive cybersecurity risk analysis in its risk acceptance memorandums as primary factors for the downgrade. The OIG highlighted that 35 systems were operating with expired or missing authorizations, and the CFPB had not established or communicated cybersecurity risk profiles in line with the NIST framework. These deficiencies were exacerbated by staffing cutbacks and a lack of contractor support for continuous security monitoring and testing.
Despite these setbacks, the remaining CFPB staff have initiated efforts to strengthen the agency's cybersecurity posture, including the development of a formal ransomware response process and the implementation of weekly cyber risk management meetings. However, the continued use of obsolete software and the lack of a robust risk management framework leave the CFPB's sensitive data—including personal and confidential supervisory information—at heightened risk. The OIG's findings underscore the urgent need for the CFPB to address these gaps to restore the effectiveness of its cybersecurity program and safeguard critical information assets.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
An audit reported that the Consumer Financial Protection Bureau's information security posture had deteriorated, with its cybersecurity program weakened as layoffs and staffing reductions affected operations. The reporting indicates a decline in the agency's security capabilities rather than a single breach event.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.