How whistleblowers actually get identified #
Discussions of whistleblowing confidentiality usually start with encryption and external attackers. The published enforcement cases tell a different story. In each of them, the threat to the reporter came from inside the organisation, from people and systems doing what they normally do.
Three cases show three different routes.
The CEO who asked security to find the writer #
In June 2016 members of the Barclays board received anonymous letters raising concerns about a senior executive the chief executive, Jes Staley, had recruited. On 28 June Staley instructed the bank’s Group Security function to identify the author of the first letter.
The bank’s whistleblowing team told Group Security that tracing the author of an anonymous letter was not acceptable. Staley told Group Security to continue.
In May 2018 the UK’s Financial Conduct Authority and Prudential Regulation Authority fined Staley £642,430, the first case either regulator brought under the Senior Managers Regime. Barclays cut his bonus by £500,000. In December 2018 the New York Department of Financial Services fined the bank itself $15 million, finding that Staley had gone ahead despite advice from the Group Chief Compliance Officer and the General Counsel. (FCA final notice , NYDFS )
The bank had a whistleblowing policy and a team that applied it correctly. It could not stop the most senior person in the organisation from overriding it. That is a structural question, and it is answered by who can see a case, and who cannot.
The legal hold that named the reporter #
Anthony Menendez worked in Halliburton’s accounting function. He raised concerns about revenue recognition internally, under his own name, and filed a confidential complaint with the SEC.
When the SEC told Halliburton to preserve documents, the general counsel concluded that Menendez was the source. He emailed Menendez’s manager and others that “the SEC has opened an inquiry into the allegations of Mr. Menendez.” The manager forwarded it to fifteen people in Menendez’s team. Colleagues stopped working with him.
In November 2014 the US Court of Appeals for the Fifth Circuit upheld the finding that this disclosure was unlawful retaliation under the Sarbanes-Oxley Act. (Fifth Circuit opinion )
The disclosure happened in a routine legal email. His internal report had carried his name and arrived from his work account, and once the case moved around the organisation, his identity moved with it.
The firewall that logged every visit #
The Azienda Ospedaliera di Perugia in Italy ran a web-based whistleblowing application. Access to it went through the hospital’s firewall, which, as firewalls do, logged connections: the IP address of the device and the username of the person. The logs were kept until the file reached 150 GB.
In April 2022 Italy’s data protection authority fined the hospital €40,000, and fined the vendor that supplied the application another €40,000 for hosting it with a third party the hospital had never authorised. The vendor’s application used HTTPS and encrypted report content. None of that helped, because the identifying record was made before any request reached it. (Garante order against the hospital , against the vendor )
What the three have in common #
In each case the organisation had a whistleblowing channel. In each case the risk came from something ordinary: an instruction from the top, a forwarded email, a network log. The Directive’s confidentiality requirement in Article 16 covers the reporter’s identity and “any other information from which the identity of the reporting person may be directly or indirectly deduced.” That includes logs, case files and access rights, along with the report itself.
For an organisation assessing its own channel, three questions follow from these cases:
- Who can see a case? Can access be restricted so that the people named in a report, including senior management, cannot open it?
- Where does identity travel? Is the reporter’s identity held apart from the case content that investigators share?
- What records the connection? Which systems between the reporter and the channel log IP addresses or accounts, including your own network if the channel is reachable only from inside it?
A longer version of these questions, one per enforcement case, is in eight questions for your whistleblowing vendor . All published decisions we track are in the whistleblowing failures register .
Last updated: