RealCyberNews
Back to latest
criticalJune 4, 2015 · 4 min read

The OPM Breach: When Hackers Stole the Government's Background-Check Files

In 2015, state-linked hackers stole security-clearance records — including fingerprints — for 21.5 million people. It remains one of the most damaging government breaches ever disclosed.

By RealCyberNews Editorial Team

Share

Most breaches expose passwords or credit card numbers — things that can be changed. The 2015 breach of the US Office of Personnel Management exposed something that can’t: fingerprints, and the deeply personal details federal employees and contractors disclose during background investigations for security clearances.

What OPM actually is

OPM is the federal government’s HR department — it processes security clearance applications for federal employees, contractors, and military personnel. Those applications, called SF-86 forms, ask for an extraordinary amount of personal detail: past addresses, foreign contacts, financial history, mental health treatment, family members’ information.

What was stolen

Investigators attributed the intrusion to a state-sponsored group, believed to have had access to OPM’s networks for close to a year before discovery. The stolen data included background-investigation records for 21.5 million people, and separately, fingerprint data for 5.6 million of them — the first confirmed large-scale theft of biometric data from a government system.

Why this breach is different

A stolen password can be reset. A stolen credit card can be cancelled. Fingerprints and the contents of a security-clearance investigation — years of financial history, foreign contacts, personal admissions made in confidence to investigators — can’t be reissued. For people whose clearance files were stolen, intelligence officials warned the exposure could pose risks for years, including the risk of foreign intelligence services using the data to identify or pressure intelligence personnel.

What to actually do about it

  • If you held a federal security clearance around 2015, OPM’s breach notifications and the identity-protection services offered afterward are worth taking seriously even years later — this wasn’t a “change your password” incident.
  • Understand the broader lesson: government systems holding background-investigation data are high-value targets specifically because that data can’t be reissued, which is why agencies have since pushed for stronger encryption and access controls on this category of record.
  • This incident is often cited as a turning point in how seriously the US government treats cybersecurity for systems holding sensitive personnel data — a useful piece of context whenever new federal cybersecurity policy references “lessons from OPM.”

Worried this affects you?

Check whether your email address has shown up in this breach — or any other — in seconds.

Run a free breach check →