BlackLeafwatch the watchmen
Bureau of Labor Statistics data-release safeguards

BLS's CPI and Jobs Data Leaked Three Times in 2024

Summary

A Department of Labor Inspector General audit found the Bureau of Labor Statistics let market-moving economic data reach outsiders early, late, or off the record three separate times in 2024: CPI and Real Earnings figures reached 72 internet providers 31 minutes before the scheduled release, a jobs-data benchmark went out by phone and email to anyone who called during a 34-minute delay, and internal CPI methodology went to 76 external recipients at banks, investment firms, and trading companies ahead of the public. Each time, BLS announced a fix. Each time, the fix went untested against the next failure -- including a crisis-communication plan that broke the day after BLS rehearsed it.

By Marcus Aurelius · July 20, 2026

The title of the Department of Labor Inspector General's June 2026 audit says "reduced risk" of leaking its own economic data early. The report underneath that title describes three separate incidents in 2024 where it didn't: CPI and Real Earnings figures reached 72 internet providers 31 minutes before the scheduled release; a jobs-data benchmark went out by phone and email to whoever called during a 34-minute delay; and internal CPI methodology -- material never intended for the public -- reached 76 people at banks, investment firms, and trading companies across three separate emails. Each incident produced a fix. None of the fixes were tested against the failure mode that came next.

31 minutes, 72 providers, one contractor two minutes early

On May 15, 2024, a BLS IT contractor started the process of moving CPI and Real Earnings data to the public server at 7:58 a.m. instead of the authorized 8:00 a.m. -- two minutes early. That should not have mattered: 's new data-replication software was supposed to block any public copy before 8:30 a.m. Instead, gaps in the software let an automatic task publish the data at 7:59 a.m., 31 minutes ahead of schedule, after the software found an alternate server port and file-transfer method once its designated one was blocked by 's firewall rules. Seventy-two internet service providers accessed the data during the 31-minute window before the official release.

The audit found the real failure predates the incident: could not produce the documentation its own Configuration Management Plan requires for a change this size -- no support-ticket record of who reviewed or authorized it, no security-impact evaluation, and a lost version history, blamed on staffing turnover during the rollout. The software that eventually leaked the data was tested only against scenarios where staff followed the process correctly. Neither policy nor its draft testing procedures required what auditors call "negative testing" -- deliberately trying to break the safeguard with an early start, a wrong port, an invalid input -- the exact failure that happened for real three months after the software went live.

Data released early
31 min
CPI/Real Earnings, May 15, 2024
Got early access
72 ISPs
during the 31-minute window
Release delayed
34 min
CES benchmark, Aug. 21, 2024

Whoever called got the number first

The second incident needed no software bug. On August 21, 2024, 's Current Employment Statistics preliminary benchmark -- normally published quietly once a year through a manual workaround -- missed its 10:00 a.m. release by 34 minutes because a manually inserted file kept the previous day's timestamp, and 's own safeguards block anything modified outside a 90-minute pre-release window. During those 34 minutes, callers and emailers asking why the website still showed last year's numbers got an answer: a supervisor cited what the audit calls an informal CES Program policy and had the still-unpublished figures emailed to customer-service staff, who then read them out by phone or sent them by email -- to whoever happened to ask, before the public release. has had trouble publishing this same benchmark in three of the last four years.

"Super users" that, BLS says, don't officially exist

The third incident is the one with no leaked file, only leaked explanations. Between January and February 2024, a BLS employee sent internal CPI methodology explanations to external users in three separate emails -- 19 recipients, then 7, then 50 -- after banks, investors, and traders asked about an unexplained used-car pricing change and an odd pattern in the shelter-cost data. The employee copied and pasted internal, jargon-heavy explanations from subject-matter experts straight into the external replies; one, on February 15, included an inaccurate conclusion about the shelter-data anomaly that wasn't corrected publicly until published its own explanation two weeks later and held a webinar the week after that. Internally, the employee labeled the recipients "super users." The audit's finding on that label is exact: insists it maintains no such formal group or list -- but for three straight events, the same term captured the same practical reality, a subset of sophisticated market participants receiving analysis the general public did not.

How many people got CPI's internal explanations before the public did
External recipients of restricted or inaccurate CPI methodology emails, Jan.-Feb. 2024
Jan. 31, 2024
19
Feb. 15, 2024
7
Feb. 27, 2024
50
Source: DOL OIG, Report 17-26-001-11-001 (June 2026), "BLS Improved CPI Customer Service Controls," printed pp.12-13
View data as table
Jan. 31, 202419Used-car quality-adjustment change; public fact sheet followed 2 weeks later
Feb. 15, 20247Shelter-data anomaly; included an inaccurate conclusion
Feb. 27, 202450Same shelter-data topic; caught only when a separate senior employee noticed

The CPI employee's supervisor was copied on every email and had told the employee to consult a subject-matter expert -- but never reviewed a draft before it went out. Nobody caught the pattern through the review chain at all; a different, more senior employee happened to notice the inaccurate February 27 email on their own.

The rule was: report a breach immediately. Nobody did.

has a written breach-reporting procedure and a Crisis Communication Plan that requires senior leadership be looped in within minutes. In all three incidents, staff went around both. After the February 27 CPI email, the sender's supervisor had it retracted -- 90 minutes later -- instead of reporting a breach; the office's Associate Commissioner learned what happened from a post on X. After the May 15 early release, a IT Specialist spotted the leaked data at 8:19 a.m., 20 minutes after it actually went live, but the chain of notifications took roughly another 36 minutes to reach the Commissioner. And on August 21, the Crisis Communication Plan calls for senior leadership to be told within 5 minutes of a reported crisis; it took 47 minutes from the scheduled release time -- and by then, senior leadership had already found out not from 's own reporting chain, but from the Department of Labor's Director of Public Affairs.

How long it took BLS leadership to find out
Minutes from the incident to senior leadership being informed
May 15 (early release)
56
Aug. 21 (delayed release)
47
Feb. 27 (restricted email)
90
Source: DOL OIG, Report 17-26-001-11-001 (June 2026), "Other Matter," printed pp.15-17
View data as table
BLS's own procedures set a target response time for each incident type; the audit's timeline shows the actual gap before senior leadership was informed. The Aug. 21 crisis-team target (5 minutes) comes from BLS's own Crisis Communication Plan; the breach-account requirement for the other two comes from BLS Administrative Procedure 20-1.

That last failure carries a detail the audit states almost in passing: BLS's Crisis Communication Plan, dormant since its 2017 creation, only "resurfaced" in August 2024 after the Communications Director who maintained it had left. ran a tabletop exercise on August 20, 2024, walking staff through exactly this scenario -- an early release, a late release, a damaging public statement. The plan failed for real the very next morning.

  • 's own audit title -- "reduced risk" -- describes what happened after three 2024 incidents, not what prevented them. CPI/Real Earnings data reached 72 internet providers 31 minutes early on May 15; a jobs-benchmark delay let phone and email requesters get the number 34 minutes before the public on Aug. 21; and 76 external recipients across three emails got internal CPI analysis in January and February -- all before the DOL Inspector General's June 2026 audit.
  • Each fix was announced, not tested against what happened next. The May 15 replication software was never "negative tested" for an early start before it leaked data early; 's informal CES release policy wasn't addressed until after it produced an inequitable release in August; the CPI Program had no formal procedure for handling sophisticated outside questions until after three emails already went out under an internal label -- "super users" -- that says has no official standing.
  • 's own breach-reporting and crisis-communication procedures were bypassed in all three incidents, including one where a retraction replaced a report and another where the Department of Labor's own public-affairs office, not 's chain of command, was the first to tell senior leadership what had happened.
  • The Inspector General made only two recommendations, both narrow -- finalize testing procedures and reference an existing restricted-information order in CPI training -- and notes that agreed with the substance but did not commit to specific corrective actions in writing. Neither nor had examined 's disclosure controls in the five years before this audit.

This piece draws entirely on the DOL Inspector General's June 26, 2026 report, fetched directly from oig.dol.gov and read page-by-page. The audit's scope covers only the three named 2024 incidents and 's response, not a general review of data security; its "super user" email evidence came from records already released under . Minute counts for notification delays (36, 24, and 90 minutes in the analysis above) are this piece's own arithmetic on times the report states directly or as "approximately" -- the report itself does not total them. No dollar figure is at stake in this audit; the finding is about data-release integrity, not spending.

Sources(1) ▾
  • U.S. Department of Labor, Office of Inspector General, BLS Reduced Risk of Improper Disclosure of Essential Economic Information Yet Additional Improvements Are Needed (Report 17-26-001-11-001) (2026-06-26)The full 24-page performance audit of 's response to three 2024 incidents in which essential economic information (CPI/Real Earnings, the CES preliminary benchmark, and internal CPI methodology) was released early, late, or to a restricted group ahead of the public. Fetched directly from oig.dol.gov and converted with pdftotext -layout. Used for every figure in this piece: the three incident narratives (Results of Audit, printed pp. 3-17), the communication-procedure failures (Other Matter, printed pp. 15-17), the recommendations and 's response (printed pp. 18-24), and the scope/methodology (Appendix A, printed pp. 21-23). A Wayback Machine capture of this exact URL succeeded on 2026-06-30, before this iteration's research began. oig.dol.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account