What Was the OPM Breach? The One That Does Not Expire

Standard Form 86 asks you to list your relatives. Then it asks about the ones who are not US citizens, where they live, and when you last had contact with them.

It asks for every address you have lived at, going back years. Every job. Every foreign country you have visited and why. Your debts, your bankruptcies, your arrests, your drug use, your alcohol use, and whether you have ever received counselling or treatment for a mental health condition.

Then investigators go and interview the people you named, and write down what those people said about you, and that goes into the file too.

In 2015 the United States government lost 21.5 million of those files.

What was the OPM breach?

Two separate intrusions into the Office of Personnel Management, the agency that functions as the federal government's HR department and, critically, runs background investigations for security clearances. They were announced separately, and the second one is the one that matters.

  • 4 June 2015 — OPM announced that personnel records for approximately 4.2 million current and former federal employees had been taken. Names, Social Security numbers, dates and places of birth, job history.
  • 9 July 2015 — OPM announced that the background investigation databases had also been taken. That number was 21.5 million.

The intrusions ran from roughly May 2014 into April 2015, with the attackers actively exfiltrating for much of that window. Initial access to the background investigation systems is generally traced to credentials belonging to a contractor rather than to an exploit — valid logins, used by the wrong people, for months.

The 1.8 million who never applied

Here is the number that almost never gets quoted, and it is the one that should be.

Of the 21.5 million, 19.7 million were people who had applied for a background investigation themselves. Employees, contractors, applicants — people who filled in the form knowing what they were handing over, in exchange for a clearance.

The other 1.8 million had not applied for anything. They were spouses and cohabitants: people who appeared on somebody else's SF-86 because the form requires it, and who were therefore in a federal database they had never heard of, had never consented to, and could not have opted out of.

They had no relationship with OPM at all. Their exposure was a consequence of who they were married to or who they lived with.

And that is only the ones counted. Every SF-86 also names references, former neighbours and foreign contacts, all recorded, none of them counted in the 21.5 million.

The fingerprints, and the revision

In the July announcement, OPM said that 1.1 million of the stolen records included fingerprints.

On 23 September 2015, after further work with the Department of Defense, it corrected that figure. The real number was 5.6 million — a five-fold increase, announced quietly, ten weeks after the fact, without changing the headline 21.5 million.

The revision matters for two reasons. The obvious one is scale. The less obvious one is that it took the government five months from discovery to establish how much biometric data had left, which tells you what the logging on those systems looked like.

OPM's statement at the time noted, fairly, that the ability to misuse stolen fingerprint data was then limited, while adding that this could change over time as technology evolved. That is an unusually honest sentence for a breach notification, and it is also the problem stated precisely. The data does not expire, so the question is not what can be done with it now.

Why credit monitoring was the wrong remedy

Affected individuals were offered credit monitoring and identity theft insurance, eventually for ten years, at considerable cost.

For the 4.2 million personnel records, that is a reasonable fit. Social Security numbers and dates of birth are the raw material of financial identity theft, and monitoring is the standard countermeasure.

For the background investigation files it is close to irrelevant, because financial fraud is not what an SF-86 is useful for.

What it is useful for is knowing which US government employees have debts, which have undisclosed relationships, which have foreign relatives in a particular country, and which have sought treatment for something they would rather their employer had not seen. That is a targeting database for recruitment and coercion, and no credit bureau alerts you when it is consulted.

There is a further inference that costs nothing to draw: a comprehensive list of cleared personnel is also, by omission, informative about people who ought to appear on it and do not.

The resignation

OPM's director, Katherine Archuleta, told reporters on Thursday 9 July that she would not be stepping down and intended to stay and fix the agency's security.

She went to the White House on the morning of Friday 10 July and offered her resignation. It was accepted. Less than twenty-four hours.

The subsequent congressional investigation was blunt about the preceding years: the agency's own Inspector General had been flagging serious information security weaknesses in annual reports well before the intrusion, including systems operating without valid authorisation. The findings were on the record. The intrusion was, in the report's framing, foreseeable.

What changed

Some of it was real. The federal government ran a Cybersecurity Sprint in mid-2015 that pushed multi-factor authentication for privileged users across agencies far faster than any normal programme would have. Background investigations were eventually moved out of OPM to a new defence-run organisation.

But the honest assessment is that the response addressed the network and not the data model. The reason a single agency compromise exposed 21.5 million people, including 1.8 million who had never applied, is that the records were aggregated that way in the first place — decades of the most sensitive personal disclosures the state collects, held in one place, on systems the agency's own auditors had been writing warnings about.

The part that does not expire

Most breaches have a half-life. Cards get reissued. Passwords get rotated. Eighteen months on, the stolen copy is inert, and that is why the industry's playbook — notify, monitor, reset — mostly works.

Nothing in an SF-86 rotates.

A Social Security number can, with difficulty, be reissued. An address history cannot be un-disclosed. The names of your foreign relatives cannot be recalled. The fact that you sought counselling in a particular year is now permanently known to whoever holds the file. And a fingerprint is the same fingerprint at sixty as it was at twenty-five.

The people affected in 2015 are, most of them, still working. The data is exactly as accurate today as it was the day it left.

Further reading

  • US House Committee on Oversight and Government Reform — The OPM Data Breach: How the Government Jeopardized Our National Security for More than a Generation, September 2016.
  • OPM — cybersecurity incident announcements of 4 June and 9 July 2015, and the fingerprint revision statement of 23 September 2015.
  • Congressional Research Service — Cyber Intrusion into U.S. Office of Personnel Management: In Brief, R44111.
  • OPM Office of the Inspector General — annual FISMA audit reports, 2012 through 2015.
  • Standard Form 86, Questionnaire for National Security Positions — read it once and the breach explains itself.

EXHIBIT 0024 — OPM

We put it on a shirt. A ten-print fingerprint card drawn as an engraving, lying on a desk with an open ink pad and a roller beside it, the ten boxes filled. Headed SF-86. Stamped in the serial box: 5,600,000.

The callouts carry the rest — 21.5 MILLION RECORDS, 1.8 MILLION NEVER APPLIED, SPOUSES AND COHABITANTS, A FINGERPRINT DOES NOT REISSUE — and the line at the bottom is the whole exhibit: nothing about this one expires.

That's the whole idea.

View the OPM shirt — EXHIBIT 0024

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.