The US Office of Personnel Management (OPM) announced on 4 June 2015 that hackers had stolen personnel records of around 4 million current and former federal employees. A second, related intrusion into OPM’s background investigation databases, disclosed on 9 July, proved far larger.
What happened
- The first breach, eventually put at around 4.2 million people, exposed personnel records including Social Security numbers.
- The background investigation breach affected 21.5 million people, including 19.7 million who had applied for security clearances and 1.8 million others, mostly their relatives, with data including employment, family, health, and financial histories.
- In September 2015 OPM raised its estimate of stolen fingerprint records from 1.1 million to 5.6 million.
- US officials and lawmakers were reported to suspect China; the Chinese government rejected the accusations as groundless.
Why it mattered
The theft of detailed security clearance files represented a lasting counter-intelligence risk, as the information, including fingerprints, cannot be reissued or changed.
Lessons for organisations
Know where your most sensitive data sits, prioritise encryption, multi-factor authentication, and network segmentation for it, and remember that biometric data needs especially strong protection because it cannot be replaced.
Sources: Federal News Network, The Washington Post
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.