Loose IT security controls could have made it possible for a malicious employee, or an external party with access to that employee's account, to gain full control of the FHFA network.
Any regulatory action resulting from the CFPB’s recent request for information must be grounded in the bureau’s statutory authority, the Mortgage Bankers Association said.