ZeroHour
CyberScooppublished ()ingested @snlyngaas

Mulvaney: CFPB hit by over 200 data 'lapses'

criticalData breach exploited in the wildimportance 60
Tagsbreach
Full article717 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Mick Mulvaney revealed Thursday that the agency had suffered some 240 “lapses” in data security over an unspecified time period, in addition to a suspected 800 other such incidents.

Mick Mulvaney
(Flickr / <a href="https://flic.kr/p/24Hay4E">Gage Skidmore</a>)

The head of the Consumer Financial Protection Bureau said Thursday that the agency had suffered some 240 “lapses” in data security over an unspecified time period, in addition to a suspected 800 other such incidents.

“We have been able to document about 200-odd – I think 240 – lapses in our data security,” acting CFPB Director Mick Mulvaney told the Senate Committee on Banking, Housing, and Urban Affairs during a hearing on the bureau’s semi-annual report to Congress.

“Lapses – is that a breach?” Sen. David Perdue, R-Ga., asked Mulvaney during a tense exchange.

“I think data got out that should not have gotten out,” Mulvaney replied, adding, “there’s another 800 [incidents] that we suspect that we haven’t been able to confirm.”

As part of its mandate to protect consumers, the CFPB has the right to collect data on credit card transactions, mortgages, and car loans, Mulvaney said.

“Everything that we keep is subject to being lost,” added Mulvaney, who is also the director of the White House Office of Management and Budget.

He consulted with an aide during the hearing to confirm that some of his agency’s data is stored by third parties.

Perdue requested a classified briefing on the subject and Mulvaney said he would be willing to provide one.

Since the seminal 2015 breach of the Office of Personnel Management, in which the personal information of some 22 million Americans was compromised, U.S. lawmakers and agencies have woken up to the threat of large-scale espionage via data theft.

In September, credit reporting company Equifax disclosed that hackers had breached the personal information, including Social Security numbers, of more than 140 million consumers in the United States.

UPDATE: A CFPB spokesperson provided the following statement to CyberScoop:

“Prior to Acting Director Mulvaney’s appointment (in November 2017), there were 233 confirmed breaches of consumer personally identifiable information (PII) within the Bureau’s Consumer Response system by the Bureau or its contractor, and at least another 840 suspected PII breaches by financial institutions using the company portal.”

More Scoops

Demonstrators raise signs and posters outside Consumer Financial Protection Bureau headquarters on Feb. 10, 2025 in Washington, D.C. (Photo by Jemal Countess/Getty Images for MoveOn)

CFPB to withdraw rule targeting data brokers

The Trump administration’s CFPB nominee spoke positively in February about the Biden-era rule to regulate the sale of Americans’ personal data, but he is now slotted instead…

Jonathan McKernan, nominee for director of the Consumer Financial Protection Bureau, testifies at a hearing of the Senate Banking Committee on Feb. 27, 2025 at the Dirksen Senate Building in Washington, D.C. (Photo by Kayla Bartkowski/Getty Images)

CFPB nominee signals openness to continuing data-broker work

The entrance to the Consumer Financial Protection Bureau (CFPB) headquarters building is seen on August 18, 2024, in Washington, DC. (Photo by J. David Ake/Getty Images)

CFPB proposes new rule to regulate expansive data broker industry

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/mick-mulvaney-cfpb-data-breach/