Senate Democrats are raising alarms about what they call a dangerous erosion of the Consumer Financial Protection Bureau’s ability to safeguard consumer data, pointing directly at actions taken by Acting Director Russell Vought and the Trump administration.
In a sharply worded letter sent earlier this week, five Senate Democrats — led by Sen. Mark Warner [D-Va.] and Sen. Elizabeth Warren [D-Mass.] — warned that the CFPB’s information security posture has “precipitously” deteriorated, citing findings from an October 31 report by the CFPB’s Office of Inspector General. The OIG reported that the bureau’s cybersecurity maturity dropped from level 4 to level 2 in the past year, concluding the agency’s system is “not effective” at protecting sensitive data.
According to the OIG, the steep slide in cybersecurity protections stems from:
- Loss of contractor support for cyber operations, information security continuous monitoring, and security controls testing, after numerous contracts were terminated early in 2025.
- Staff departures, including the chief risk officer and information security personnel, whose jobs have not been backfilled.
- Work stoppages and restructuring directives that left key programs “on hold” and operational capacity weakened.
Court filings cited by lawmakers indicate that nearly $200 million of the CFPB’s $227 million in contracts were terminated early this year, with only a small fraction reinstated. Senators said these actions “have real consequences for the American public,” including reducing the agency’s ability to protect personal financial information.
Political and Legal Tensions Intensify
Vought has previously stated publicly that he intended to “close down” the CFPB and did not request congressional funding for the agency through the end of FY 2025. Meanwhile, the administration has argued in court that CFPB’s funding mechanism is unlawful — a dispute that has limited its ability to formally reorganize or shut down the bureau.
“These actions have real consequences… including the ability of the agency to protect the sensitive personal information of American consumers and businesses,” the senators wrote.
The letter demanded detailed answers from Vought, including:
- Which contracts previously supported cybersecurity operations
- Which were terminated
- Which were reinstated, if any
- How terminations affected the agency’s security readiness




