A contractor providing information technology security services for Amtrak violated company policies by wrongfully uploading sensitive and proprietary Amtrak data to his personal Google cloud storage and a personally owned USB flash drive without company knowledge or approval. Our agents were able to identify and remove the company’s data from his cloud storage and flash drive. In addition, the company has remediated certain vulnerabilities and continues to take steps to address security weaknesses identified as part of our investigation.
Report File
Date Issued
Submitting OIG
Amtrak (National Railroad Passenger Corporation) OIG
Other Participating OIGs
Amtrak (National Railroad Passenger Corporation) OIG
Agencies Reviewed/Investigated
Amtrak (National Railroad Passenger Corporation)
Report Number
OIG-WS-2020-328
Report Description
Report Type
Investigation
Agency Wide
Yes
Additional Details