In June 2015, the US Office of Personnel Management announced that it had suffered a data breach affecting approximately 4.2 million current and former federal employees. Within weeks, the scope expanded dramatically: a second, related breach had compromised the background investigation records of 21.5 million individuals who had applied for security clearances. This second dataset was qualitatively different from most data breaches - it contained not just names, addresses, and Social Security numbers, but the deeply personal information collected during security clearance investigations: foreign contacts, financial histories, mental health information, sexual histories, drug use, and the names and personal details of every family member, neighbor, and reference contact the applicants had listed.
The OPM breach was attributed to Chinese intelligence (MSS, Ministry of State Security) and was described by Director of National Intelligence James Clapper as "the most significant theft of government data" in US history. The database of background investigation records is effectively a comprehensive dossier on every person who has held or applied for a US security clearance - intelligence analysts, special forces operators, embassy staff, nuclear weapons engineers, CIA officers. China obtained it in its entirety.
The Attack: KeyBoy and the Long Dwell Time
OPM's network was compromised by a group the security industry tracks as APT10 (also known as Stone Panda, MenuPass). The initial access vector was a spear-phishing email containing a malicious document that installed KeyBoy, a RAT (remote access trojan) associated with Chinese state-sponsored operations. The attackers obtained credentials with domain administrator privileges and moved laterally across OPM's network.
OPM did not detect the initial compromise. The attackers had been in the network for at least a year before the breach was discovered - some estimates put the initial compromise as early as November 2013. During this dwell time, they mapped OPM's network, identified the relevant databases, and exfiltrated data over an extended period without triggering alerts.
A forensic investigation by OPM's inspector general found that OPM's security posture at the time of the breach was deeply inadequate. OPM had not maintained a comprehensive inventory of its IT systems. It had not implemented multi-factor authentication for remote access. Its network monitoring was minimal. Many of its legacy systems had not been patched for years. The 2014 OPM Inspector General report had given OPM an overall security grade of "C-" and flagged 11 major systems as operating without authorization to operate.
The Intelligence Value
The counterintelligence implications of the OPM breach are enormous and long-lasting. Former NSA and CIA director Michael Hayden said: "This is catastrophic. In the history of espionage, there's never been anything like this." Former Director of National Intelligence James Clapper called it "a goldmine for a foreign intelligence service."
The intelligence value operates on multiple timescales. Immediately, it allowed Chinese intelligence to identify Americans working undercover in China - anyone listed as employed by a cover organization while their background investigation record suggested actual CIA or DIA employment. It provided the names of every intelligence agency employee who had applied for a clearance, along with their personal contacts who could potentially be approached as recruitment targets or unwitting intelligence sources.
Over years, the database provides persistent intelligence value: it identifies individuals who reported financial stress (potential vulnerabilities for recruitment), individuals with foreign family members (potential leverage), individuals who had disclosed mental health treatment (potential vulnerabilities), and individuals who had worked in sensitive programs that no longer exist on their public-facing resumes. Chinese intelligence can cross-reference the OPM data with other intelligence to identify intelligence officers operating under unofficial cover.
The Fingerprint Database
In addition to the SF-86 background investigation records, OPM also disclosed that approximately 5.6 million fingerprint records were included in the breach. The significance of biometric data is different from text records: fingerprints cannot be changed. An intelligence officer whose fingerprints are in the OPM dataset cannot simply get new fingerprints; those records are permanent.
The practical exploitation of 5.6 million fingerprint records is limited by China's ability to collect fingerprints in contexts where the records are useful - border crossings, controlled environments. But the records are indefinitely useful for identifying undercover operators who pass through Chinese-controlled territory or any country that shares biometric data with China.
The Response and Accountability
OPM Director Katherine Archuleta resigned in July 2015, days after the full scope of the breach was disclosed. The agency offered credit monitoring to affected individuals and eventually established the MyIDCare service for breach notification and identity protection.
Congress held multiple hearings. The aftermath produced the Federal Cybersecurity Enhancement Act of 2015 and the Cybersecurity Information Sharing Act, and accelerated the rollout of the DHS Continuous Diagnostics and Mitigation (CDM) program to improve federal civilian network monitoring. The Office of Management and Budget issued new cybersecurity guidance for federal agencies.
No individuals were ever charged or sanctioned specifically for the OPM breach. The Obama administration's decision not to impose sanctions on China for the OPM hack was controversial - officials argued that espionage, unlike intellectual property theft, was a conventional intelligence activity that all major powers engaged in and that responding with sanctions would invite reciprocal action against US intelligence operations. President Obama and Chinese President Xi reached an agreement in September 2015 covering commercial cyber espionage - the theft of trade secrets for economic advantage - but explicitly excluded government-to-government intelligence collection like OPM.