Key Takeaways
- A USB drive reportedly holding Navajo veterans' personal and financial records was found in a Farmington laundromat.
- The Navajo Nation Council arranged for the Farmington FBI office to secure the device and support an investigation.
- The incident raises questions about portable-media controls, record inventories, access management and chain of custody.
A USB flash drive discovered in a Farmington, New Mexico, laundromat has triggered a Navajo Nation review of how sensitive veterans' records were stored, transported and potentially exposed. The device is now secured by the Farmington Office of the Federal Bureau of Investigation, but the scope of the incident remains undetermined.
The Legislative Branch chief legal counsel arranged the transfer on Tuesday after the matter surfaced during Monday's regular meeting of the Health, Education and Human Services Committee. The newly appointed Navajo Nation Veterans Advisory Council commander briefed the committee about the drive.
According to testimony, a Navajo veteran found the device and discovered that it reportedly contained Social Security information, DD-214 military discharge records, identification documents, W-9 forms, financial assistance applications, direct-deposit information and other personally identifiable information belonging to Navajo veterans.
That combination creates a particularly sensitive risk profile. Identification and financial records can support identity theft or payment fraud, while DD-214 forms contain extensive information about an individual's military service. The National Archives generally opens military personnel records to the public 62 years after a service member leaves the military, illustrating how long access restrictions can remain relevant.
The veteran who found the drive has remained anonymous because of concerns about possible retaliation. Information presented to the committee indicated that the veteran initially contacted the Office of the President and Vice President and the Navajo Nation Veterans Administration but had not received a response as of Monday's meeting. The veteran then contacted the Shiprock Veterans Organization commander, who alerted the HEHSC chair.
"The protection of our veterans' confidential information has to be treated as a priority," the HEHSC chair said. "These veterans entrusted their government with personal records, and we have a responsibility to determine what happened, who was responsible and what steps are necessary to protect every veteran who may have been affected."
Finding sensitive data on portable storage does not, by itself, establish that malicious access occurred. Investigators will need to determine what files are present, whether they are authentic, when they were copied, who had possession of the drive and whether evidence indicates unauthorized viewing or duplication.
Chain of custody now matters. Preserving the device without altering files or metadata can help investigators reconstruct its history. Authorities may also examine whether the drive was encrypted, password protected, inventoried or authorized for use. How did records with multiple forms of identifying and banking information end up outside a controlled workplace?
The FBI requires detailed identity information for various FOIA and Privacy Act record requests, including a dedicated Privacy Act process for people seeking their own files. Its guidance reflects a broader point for public-sector record custodians: datasets containing names, dates of birth, Social Security numbers and incident details call for tightly managed access and disclosure procedures.
The Navajo Nation Council speaker said the Council had acted to protect veterans' privacy and trust. The speaker called for authorities to determine what happened, assess the potential impact and take steps to protect veterans whose information may have been compromised.
For technology and records-management leaders, the episode highlights the risks associated with removable media. Controls described in NIST SP 800-53 can support access management, audit logging and media protection, while NIST SP 800-88 addresses sanitization and disposal. Practical measures can include approved-device inventories, encryption, restrictions on USB ports, documented transfers, retention schedules and verified destruction.
Still, controls on paper are only part of the picture. Navajo Nation reviewers will likely need to establish which office collected the records, whether copies exist elsewhere and which veterans may be affected. The answers will shape any notification, monitoring or remediation response.
No determination has yet been reported about improper access, disclosure or misuse. For now, the FBI's custody of the drive gives investigators a controlled starting point. The larger task is tracing the device back through Navajo Nation records-handling processes and identifying where those processes may have broken down.
⬇️