In June 2015, the US Office of Personnel Management announced that it had suffered a data breach affecting approximately 4.2 million current and former federal employees. Within weeks, the scope expanded dramatically: a second, related breach had compromised the background investigation records of 21.5 million individuals who had applied for security clearances. This second dataset was qualitatively different from most data breaches - it contained not just names, addresses, and Social Security numbers, but the deeply personal information collected during security clearance investigations: foreign contacts, financial histories, mental health information, sexual histories, drug use, and the names and personal details of every family member, neighbor, and reference contact the applicants had listed.

The OPM breach was attributed to Chinese intelligence (MSS, Ministry of State Security) and was described by Director of National Intelligence James Clapper as "the most significant theft of government data" in US history. The database of background investigation records is effectively a comprehensive dossier on every person who has held or applied for a US security clearance - intelligence analysts, special forces operators, embassy staff, nuclear weapons engineers, CIA officers. China obtained it in its entirety.

The Attack: KeyBoy and the Long Dwell Time

OPM's network was compromised by a group the security industry tracks as APT10 (also known as Stone Panda, MenuPass). The initial access vector was a spear-phishing email containing a malicious document that installed KeyBoy, a RAT (remote access trojan) associated with Chinese state-sponsored operations. The attackers obtained credentials with domain administrator privileges and moved laterally across OPM's network.

OPM did not detect the initial compromise. The attackers had been in the network for at least a year before the breach was discovered - some estimates put the initial compromise as early as November 2013. During this dwell time, they mapped OPM's network, identified the relevant databases, and exfiltrated data over an extended period without triggering alerts.

A forensic investigation by OPM's inspector general found that OPM's security posture at the time of the breach was deeply inadequate. OPM had not maintained a comprehensive inventory of its IT systems. It had not implemented multi-factor authentication for remote access. Its network monitoring was minimal. Many of its legacy systems had not been patched for years. The 2014 OPM Inspector General report had given OPM an overall security grade of "C-" and flagged 11 major systems as operating without authorization to operate.

[WARNING]
The OPM background investigation database contained Standard Form 86 (SF-86) data - the questionnaire all security clearance applicants complete. SF-86 asks for: every foreign national the applicant knows, has contacted, or has had a relationship with; all foreign travel in the past seven years; any mental health treatment; any drug use; financial debts and bankruptcies; every address lived at in the past ten years; names and contact information of every neighbor, colleague, and reference; details of any legal troubles. For an intelligence operative, the SF-86 is a comprehensive guide to their vulnerabilities, contacts, and cover. China obtained this information on approximately 21.5 million individuals who had undergone security clearance investigations since 2000.

The Intelligence Value

The counterintelligence implications of the OPM breach are enormous and long-lasting. Former NSA and CIA director Michael Hayden said: "This is catastrophic. In the history of espionage, there's never been anything like this." Former Director of National Intelligence James Clapper called it "a goldmine for a foreign intelligence service."

The intelligence value operates on multiple timescales. Immediately, it allowed Chinese intelligence to identify Americans working undercover in China - anyone listed as employed by a cover organization while their background investigation record suggested actual CIA or DIA employment. It provided the names of every intelligence agency employee who had applied for a clearance, along with their personal contacts who could potentially be approached as recruitment targets or unwitting intelligence sources.

Over years, the database provides persistent intelligence value: it identifies individuals who reported financial stress (potential vulnerabilities for recruitment), individuals with foreign family members (potential leverage), individuals who had disclosed mental health treatment (potential vulnerabilities), and individuals who had worked in sensitive programs that no longer exist on their public-facing resumes. Chinese intelligence can cross-reference the OPM data with other intelligence to identify intelligence officers operating under unofficial cover.

The Fingerprint Database

In addition to the SF-86 background investigation records, OPM also disclosed that approximately 5.6 million fingerprint records were included in the breach. The significance of biometric data is different from text records: fingerprints cannot be changed. An intelligence officer whose fingerprints are in the OPM dataset cannot simply get new fingerprints; those records are permanent.

The practical exploitation of 5.6 million fingerprint records is limited by China's ability to collect fingerprints in contexts where the records are useful - border crossings, controlled environments. But the records are indefinitely useful for identifying undercover operators who pass through Chinese-controlled territory or any country that shares biometric data with China.

[TECHNICAL NOTE]
The OPM breach led to the identification and shutdown of CIA informant networks in China. In 2017, the New York Times and others reported that China had systematically dismantled CIA human intelligence operations in China starting around 2010, killing or imprisoning at least 20 CIA sources between 2010 and 2012. The cause was debated - the CIA initially suspected a mole (who was later identified: Jerry Chun Shing Lee, convicted in 2019), but the OPM data may have contributed independently. If China could cross-reference CIA officer backgrounds against the OPM records, they could identify cover identities and trace network connections. The OPM breach and the CIA network dismantling occurred on overlapping timelines with the breach having potentially amplified whatever other intelligence was being used to identify sources.

The Response and Accountability

OPM Director Katherine Archuleta resigned in July 2015, days after the full scope of the breach was disclosed. The agency offered credit monitoring to affected individuals and eventually established the MyIDCare service for breach notification and identity protection.

Congress held multiple hearings. The aftermath produced the Federal Cybersecurity Enhancement Act of 2015 and the Cybersecurity Information Sharing Act, and accelerated the rollout of the DHS Continuous Diagnostics and Mitigation (CDM) program to improve federal civilian network monitoring. The Office of Management and Budget issued new cybersecurity guidance for federal agencies.

No individuals were ever charged or sanctioned specifically for the OPM breach. The Obama administration's decision not to impose sanctions on China for the OPM hack was controversial - officials argued that espionage, unlike intellectual property theft, was a conventional intelligence activity that all major powers engaged in and that responding with sanctions would invite reciprocal action against US intelligence operations. President Obama and Chinese President Xi reached an agreement in September 2015 covering commercial cyber espionage - the theft of trade secrets for economic advantage - but explicitly excluded government-to-government intelligence collection like OPM.

[IOC]
APT10 (Stone Panda/MenuPass) indicators associated with the OPM operation: KeyBoy malware hashes published by Trend Micro (2013, 2016 variants); multiple C2 domains documented by CrowdStrike, Fireeye, and others - historical infrastructure includes domains mimicking legitimate software vendors. Network: APT10 commonly used legitimate remote access tools (VPN tunneling, Citrix) after initial compromise, making detection via signature matching ineffective. Post-OPM defensive requirements: MFA for all remote access to government systems (now mandated via OMB M-22-09 zero trust policy); network segmentation between unclassified and sensitive systems; DLP controls on bulk database exports; baseline user and entity behavior analytics to detect large data transfers. The SF-86 compromise remains active counterintelligence risk through 2030s given the persistent intelligence value of the records obtained - there is no remediation for information that has been disclosed.