
THE NRC FILES: WHAT THE U.S. NUCLEAR REGULATORY COMMISSIONโS CLOSED 2025 INVESTIGATIONS REVEAL
A BerndPulch.org OSINT examination of government-card misuse, conflicts of interest, private businesses conducted during duty hours, cybersecurity cases and regulatory oversight failures
BERNDPULCH.ORG โ OSINT INTELLIGENCE DESK
AUGUST 13, 2026
INSIDE THE PAPER TRAIL OF AMERICAโS NUCLEAR REGULATOR
The U.S. Nuclear Regulatory Commission exists to perform one of the most consequential regulatory functions in the United States: overseeing civilian nuclear activities and protecting public health and safety.
But the NRC’s own Inspector General investigative files reveal another layer of the institution.
The document reviewed by BERNDPULCH.ORG is a collection of NRC Office of Inspector General investigations closed during calendar year 2025. The underlying material was released following a Freedom of Information Act request dated April 21, 2026, with the NRC OIG identified as the originating agency.
The cases cover an unusually broad range of internal-control and integrity issues.
They include:
- unauthorized use of government travel cards;
- alleged personal business conducted during government working hours;
- use of government equipment for private activity;
- potential conflicts of interest;
- prohibited securities;
- falsified time reporting;
- cybersecurity and forensic investigations;
- management documentation failures;
- alleged inappropriate interactions with regulated entities.
The files do not establish that the NRC as an institution is corrupt.
They establish something more useful for an OSINT investigation:
The regulator itself has a substantial internal oversight system dealing with allegations of misconduct, ethics violations, management failures and security concerns.
I. THE $26,174.86 TRAVEL-CARD CASE
One of the clearest documented cases concerns an NRC employee’s government travel charge card.
According to the OIG material, investigators reviewed official travel authorizations and U.S. Bank travel-card records covering April 10, 2019 through December 31, 2024.
The investigation identified 504 unauthorized transactions totaling $26,174.86.
The records were divided into two periods.
From April 2019 through January 22, 2024, investigators identified 309 transactions totaling $18,188.44.
A subsequent review covering January 22 through December 31, 2024 identified another 195 transactions totaling $7,986.42.
The OIG found no evidence that the government suffered a pecuniary loss from the unauthorized transactions in the particular case described in the document.
But the conduct raises a fundamental control question:
How did hundreds of unauthorized transactions pass through a federal government travel-card system before the matter was resolved?
II. THE CASINO CASH-ADVANCE TRAIL
The case becomes more unusual when the investigators examined the underlying bank records.
During an interview, the employee acknowledged using the NRC travel card for personal expenses.
The OIG reviewed U.S. Bank records and found multiple cash advances at casinos. The employee acknowledged making the transactions and indicated that some may have occurred during personal travel.
This is important because federal travel cards are not ordinary personal credit cards.
The OIG documentation cites federal ethics requirements stating that government property must be protected and conserved and may not be used for unauthorized purposes.
The case therefore illustrates the importance of something much broader than the dollar value involved:
Internal controls are only as strong as the mechanisms that detect violations.
III. THE PROHIBITED-SECURITY INVESTIGATION
Another case examined a potential conflict involving ownership of a prohibited security.
The OIG investigated whether an NRC employee had owned a prohibited security and whether the employee’s official work created a conflict.
Investigators examined:
- time-and-attendance records;
- NRC document systems;
- project milestones;
- PowerBI dashboards;
- MapAnalytics;
- public meeting schedules;
- information supplied to NRC officials;
- open-source information concerning the company involved.
The OIG found no indication that the employee had worked on projects related to the company whose security was owned.
The security itself reportedly generated only approximately $45 in net gains while it was held.
The Office of General Counsel subsequently directed divestment and confirmed compliance with the prohibited-securities rules. The investigation was then closed without further OIG action.
This is an important distinction.
An investigation is not automatically evidence of wrongdoing.
In this case, the investigation ultimately produced a compliance action rather than a finding of a substantive conflict.
IV. THE PRIVATE REAL-ESTATE BUSINESS CASE
Another investigation demonstrates how digital records can become an evidentiary trail.
The OIG received an anonymous complaint alleging that an NRC employee was conducting a private real-estate business during government duty hours.
The complaint was particularly significant because the OIG had previously investigated similar allegations involving the same employee.
The earlier investigation had substantiated allegations that the employee conducted real-estate business during work hours and used government equipment for personal business. The agency had previously imposed a four-day suspension.
The later investigation examined whether the conduct continued.
According to the document, investigators identified 31 instances of website activity across six websites that appeared to indicate use of U.S. government equipment and government time for private real-estate activity.
This is a particularly revealing OSINT lesson.
The investigators did not necessarily need a witness to document every event.
Digital activity itself became evidence.
V. CYBER FORENSICS INSIDE THE NUCLEAR REGULATOR
The NRC OIG also maintains a Cyber Crimes Unit.
The reviewed material states that between May 2023 and September 2024, the unit completed two forensic reviews, performed two network-log reviews, and assisted with an intrusion event.
The documented casework included investigations involving:
- alleged personnel-security issues;
- alleged security violations;
- management failures in documenting interactions with licensees;
- an NRC manager operating a personal business during work hours;
- alleged falsified time reporting;
- alleged conflicts of interest;
- and other personnel-related allegations.
The cyber component matters because the modern federal workplace leaves an enormous digital footprint.
Email systems.
Network logs.
Web activity.
Document metadata.
Time-and-attendance systems.
Access records.
These can collectively reconstruct behavior that traditional interviews may never reveal.
VI. THE REGULATORY OVERSIGHT QUESTION
The most significant issue is not any individual employee.
It is the control architecture.
The NRC regulates organizations operating in one of the most safety-sensitive sectors in the United States.
That creates a fundamental institutional requirement:
The regulator must itself maintain credible integrity controls.
An agency overseeing nuclear licensees cannot afford weak internal controls.
The OIG cases therefore deserve attention not because they prove systemic misconduct, but because they show how many different categories of institutional risk must be monitored simultaneously.
Financial controls.
Ethics.
Conflicts of interest.
Cybersecurity.
Personnel security.
Time reporting.
Management documentation.
Interactions with regulated entities.
Each represents a potential vulnerability.
VII. NOT EVERY INVESTIGATION ENDS IN WRONGDOING
This is where sensational reporting can become misleading.
The files contain numerous investigations where allegations were not substantiated.
One example concerns an employee’s outside employment and telework arrangements.
The OIG found no evidence of wrongdoing or violations related to the outside employment or use of telework and issued a clearance letter, closing the investigation without further OIG action.
That distinction is essential.
An allegation is not a finding.
An investigation is not a conviction.
A referral is not proof of misconduct.
For an OSINT publication, preserving those distinctions is more important than producing the most dramatic headline.
VIII. THE $350,000 SETTLEMENT
The files also contain a settlement involving PharmaLogic Holdings Corporation, a Florida-headquartered company involved in compounding and manufacturing radiopharmaceuticals.
The United States alleged that nine entities acquired by the company improperly certified themselves as small entities in order to obtain reduced NRC annual fees.
According to the settlement document, the conduct covered a period from approximately March 31, 2015 through December 31, 2023.
The agreement required PharmaLogic Holdings Corporation to pay $350,000, including $195,600 in restitution. The settlement explicitly states that it was not an admission of liability by the company.
Again, precision matters.
The document records government allegations and a settlement, not a judicial finding that every allegation was proven.
IX. WHAT THE FILES ACTUALLY SHOW
After examining the cases, several patterns emerge.
1. INTERNAL OVERSIGHT IS MULTI-LAYERED
The NRC OIG does not investigate only financial misconduct.
Its work spans ethics, cybersecurity, personnel, management, regulated entities and government resources.
2. DIGITAL FORENSICS HAVE BECOME CENTRAL
Website activity, network logs, document systems and electronic records can become critical evidence.
3. GOVERNMENT RESOURCES REQUIRE CONSTANT MONITORING
Travel cards, computers, networks and working time can all become areas of abuse.
4. INVESTIGATIONS CAN END WITHOUT A FINDING OF WRONGDOING
This is essential when interpreting government investigative files.
5. REGULATORY INTEGRITY IS ITSELF A SECURITY ISSUE
A nuclear regulator depends upon public confidence in its independence, competence and internal controls.
X. THE OSINT ANGLE
The most interesting lesson from these files may be methodological.
Modern investigations increasingly combine traditional investigative techniques with digital evidence.
Consider the real-estate investigation.
An allegation became testable because investigators could examine website activity.
Consider the prohibited-security investigation.
Investigators combined official agency records with open-source information.
Consider cybersecurity investigations.
Network logs and forensic examinations created additional evidentiary trails.
This is precisely where OSINT becomes powerful.
A single data point may mean little.
But when multiple independent records converge, they can establish a much stronger chronology.
Website activity + timestamps + government equipment + travel records + financial records + official documents
can produce an investigative picture far more detailed than any individual source.
XI. THE BIGGER QUESTION: WHO WATCHES THE WATCHERS?
The NRC’s mission makes this question unusually important.
The agency regulates nuclear activities.
Its inspectors interact with licensees.
Its officials make decisions affecting companies and facilities.
Its employees have access to sensitive government systems.
Its investigators therefore have to monitor not only external compliance but also internal institutional integrity.
That is why the Inspector General function matters.
An independent investigative mechanism provides a second layer of accountability.
And the existence of investigations should not automatically be interpreted as institutional failure.
In some cases, it demonstrates the opposite:
A functioning oversight system detected a potential problem, investigated it, documented the evidence and took corrective action.
XII. BERNDPULCH OSINT ASSESSMENT
INSTITUTIONAL RISK: MEDIUMโHIGH
EVIDENCE QUALITY: HIGH
SYSTEMIC CORRUPTION ESTABLISHED: NO
OVERSIGHT ACTIVITY: SUBSTANTIAL
The reviewed NRC OIG material does not establish a generalized corruption problem inside the Nuclear Regulatory Commission.
It does establish that the agency’s Inspector General investigated a broad spectrum of allegations and control failures.
Some investigations produced substantiated findings or corrective actions.
Others were closed without evidence of wrongdoing.
The strongest conclusion supported by the documents is therefore more nuanced:
The NRC operates under significant internal-integrity and oversight pressures, but the existence of multiple investigations should not itself be treated as evidence of systemic corruption.
The more important OSINT question is whether individual cases represent isolated failures or reveal recurring weaknesses in:
financial controls,
personnel oversight,
cybersecurity,
conflict-of-interest management,
management documentation,
and supervision of government resources.
That question requires cross-referencing the individual cases with historical OIG reports, disciplinary records, agency policies and subsequent corrective actions.
XIII. THE PAPER TRAIL IS THE STORY
The most revealing aspect of the NRC files may ultimately be the paper trail itself.
Government misconduct rarely leaves only one piece of evidence.
It can leave:
a bank transaction.
a website visit.
a network log.
an email.
a time sheet.
a meeting record.
a securities transaction.
a procurement document.
an OIG interview.
Separately, each may appear insignificant.
Together, they can reconstruct an institutional timeline.
That is the essence of modern investigative OSINT.
And the NRC files demonstrate why the principle remains powerful:
Follow the records. Follow the timestamps. Follow the money. Then verify.
SOURCE & METHODOLOGY NOTE
This investigation is based primarily on the Nuclear Regulatory Commission Office of Inspector General document โInvestigations Closed during CY2025,โ released in connection with a Freedom of Information Act request dated April 21, 2026. The document identifies the NRC OIG as the source and contains individual investigative materials, memoranda and settlement documentation.
Where the underlying documents describe allegations, this article identifies them as allegations. Where the OIG reports findings or closure decisions, those distinctions are preserved.
BERNDPULCH.ORG โ OSINT INTELLIGENCE DESK
**DOCUMENTS FIRST. CLAIMS SECOND. VERIFICATION ALWAYS.**













You must be logged in to post a comment.