← Case Files · The Breach Files
OPM, 2015: 21.5 million security clearance files, fingerprints included
- People affected
- 21.5 million background investigation records, 4.2 million personnel records, 5.6 million fingerprints
- When it happened
- 2014 – April 2015
- Made public
- June 2015
- How they got in
- Stolen contractor credentials, then malware providing persistent access
- Attributed to
- Attributed by US officials to actors working for China; never formally charged
- What it cost
- $63 million class settlement; the agency's director resigned
What was exposed: Names · Social Security numbers · Addresses · Employment and residency history · Foreign contacts · Financial difficulties · Drug use and arrests disclosed on clearance forms · Mental health history · Fingerprints
Most breaches cost people money. This one cost the United States a generation of counterintelligence cover. The Office of Personnel Management holds the background investigation files for anyone who has applied for a federal security clearance, and in 2015 it lost 21.5 million of them — along with 5.6 million sets of fingerprints.
What was in the files
To understand why this breach is in a different category, you have to understand what a completed SF-86 contains. The form is the application for a national security clearance, and applicants must disclose:
- A decade of addresses, jobs and the people who can verify them — including neighbours and references who never applied for anything.
- Every foreign contact and foreign national relationship, with names and the nature of the connection.
- Financial history: debts, bankruptcies, gambling problems, unpaid taxes.
- Arrests, drug use and alcohol problems, disclosed on the understanding that honesty is safer than concealment.
- Mental health treatment, and the details of relatives and cohabitants.
The form exists to compile, in one place, everything about a person that a hostile service might use to pressure them. Handing a completed archive of 21.5 million of these to a foreign intelligence service is, functionally, handing over the vulnerability assessment of an entire cleared workforce — plus the identities of their relatives, partners and references, none of whom ever consented to be in a government database at all.
How it happened
There were two intrusions, and OPM's own inspector general had been warning about the conditions that allowed them for years. Audit reports before 2015 repeatedly flagged systems operating without valid security authorisations, incomplete inventories and weak access controls.
The initial foothold came through credentials belonging to a contractor that carried out background investigations. Once inside, the attackers installed malware for persistent access and moved laterally. The first intrusion, involving personnel records for 4.2 million current and former federal employees, was identified in April 2015 — and identified almost by accident, during a demonstration of a security product OPM was evaluating, which flagged traffic the incumbent tools had missed.
The second discovery was the serious one. Investigating the first intrusion revealed a separate, earlier and far larger theft: the background investigation archive itself, 21.5 million records, plus 5.6 million fingerprint images. The fingerprint figure was initially reported as 1.1 million and revised upwards in September 2015 — a familiar pattern in which the first number out of the door is the one everybody remembers and the wrong one.
The timeline
- 2013–2014 — Inspector general audits repeatedly report material weaknesses in OPM's information security.
- 2014 — Contractor credentials are compromised; attackers establish persistence.
- April 2015 — A security tool under evaluation detects malicious traffic. The first intrusion is confirmed.
- June 2015 — OPM announces the theft of 4.2 million personnel records.
- July 2015 — The background investigation breach is announced: 21.5 million records. Director Katherine Archuleta resigns on 10 July.
- September 2015 — The number of stolen fingerprint records is revised from 1.1 million to 5.6 million.
- September 2016 — A House Oversight Committee report concludes the breach was preventable and that OPM's leadership had failed to act on years of warnings.
- 2022 — A $63 million class-action settlement is approved.
What it changed
Federal cybersecurity got a sprint and then a strategy. The immediate response was a government-wide "cybersecurity sprint" — patch the critical vulnerabilities, cut the number of privileged users, and get multi-factor authentication onto privileged accounts at speed. The longer consequence was the creation of the National Background Investigation Bureau and, eventually, the transfer of that function to the Department of Defense, on the reasoning that a personnel agency was never the right custodian for counterintelligence-grade data.
Contractor access became a first-class control. The credentials that opened the door belonged to a company doing investigations on OPM's behalf. This is the same failure pattern as Target's refrigeration contractor two years earlier, in a context where the consequences were national rather than financial.
Biometrics acquired a permanence problem in public. Before OPM, the argument that biometric identifiers cannot be reissued was largely theoretical. Afterwards there were 5.6 million concrete examples, and it shaped how fingerprint and face data have been regulated since.
Why it still matters a decade on
Stolen card numbers stop working. Stolen clearance files do not. A person who filled in an SF-86 in 2013 disclosing a relative abroad, a period of financial trouble and a course of counselling is still that person, and the file describing it is still accurate. The value of the archive to a foreign service is not what it enabled in 2015; it is what it enables across an entire career, as those applicants rise into more senior positions.
That is the structural point worth taking from this case: for some categories of data, the exposure window is not measured in months. It is measured in working lifetimes.
If you were in it
- Treat identity-verification questions as compromised for life. Anything a call centre might ask you to confirm — past addresses, employers, relatives' names — is in this file.
- Expect targeted approaches, not mass fraud. This data supports precise, patient social engineering rather than bulk card fraud. A message that knows your posting history and your relatives' names is the expected shape of the threat.
- Freeze credit anyway. The Social Security numbers in the file are also useful for ordinary financial fraud, and freezes are free.
- If you were a reference or relative on someone else's form, you are in the data without ever having applied. Apply the same assumptions.
Questions people ask
What is an SF-86 and why does it matter?
It is the questionnaire used for US national security positions. To be cleared, an applicant discloses every address and job for a decade, every foreign contact and foreign travel, financial problems, arrests, drug use, alcohol issues and mental health treatment — plus the names and details of relatives, neighbours and references. The form exists precisely to surface anything that could be used to pressure a person. Losing a database of completed forms hands that inventory to someone else.
Why were fingerprints a bigger deal than Social Security numbers?
Because you cannot reissue a fingerprint. A stolen identifier that can never be changed matters most for people whose work depends on not being recognised — and biometric checks at borders and in secure facilities have become far more common since 2015.
Was anyone prosecuted for the OPM breach?
No one has been charged with the OPM intrusion itself. US officials publicly attributed it to Chinese actors, and a Chinese national was later arrested over related malware used in other intrusions, but no OPM prosecution has followed.
How was it finally detected?
During a vendor demonstration. A security product being trialled at OPM flagged malicious traffic that existing tools had not, which is how the first intrusion came to light in April 2015. Investigating it uncovered the second, far larger theft of the background investigation archive.
Sources
- US House Committee on Oversight and Government Reform — "The OPM Data Breach: How the Government Jeopardized Our National Security for More than a Generation", September 2016
- OPM cybersecurity incident notifications, June and July 2015
- US Office of the Inspector General audit reports on OPM information security, 2014–2015
- In re US Office of Personnel Management Data Security Breach Litigation — $63 million settlement, 2022
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.