Between 2014 and 2015, Chinese intelligence services obtained the personnel records of 21.5 million US government employees, contractors, and their family members. The Office of Personnel Management breach was not the largest data breach in history by record count, but it may be the most damaging intelligence collection operation ever conducted against the United States. The data stolen included the SF-86 security clearance application forms - the most sensitive biographical documents the US government collects - describing the foreign contacts, financial vulnerabilities, past drug use, and personal histories of everyone who works in the intelligence community.
What OPM Held
The Office of Personnel Management maintains personnel and security clearance files for virtually every federal employee and contractor. The security clearance investigation process requires applicants to complete Standard Form 86 (SF-86), which asks for:
A complete biographical history going back 10 years or more. Every foreign contact, including names, addresses, and nature of relationship. All foreign travel. Financial history including debts, bankruptcies, and financial difficulties. Any psychological or mental health treatment. Past drug and alcohol use, including detailed descriptions. Prior employment, including any terminations. Legal history. Family members' information, including family members living abroad.
The SF-86 is designed to identify vulnerabilities that could be exploited for blackmail or coercion. A foreign intelligence service with access to the SF-86 files for the entire US intelligence community has, in effect, a comprehensive vulnerability map of American intelligence officers - who has financial problems, who has a family member in China, who has addiction history, who has psychological records that could be leveraged.
The Breach: Timeline and Discovery
The attackers - attributed to China's Ministry of State Security - first gained access to OPM's network in March 2014, using a spear phishing attack targeting OPM contractors. The initial access was used for reconnaissance; the attackers spent months mapping OPM's network architecture before accessing the actual personnel database.
A second intrusion, likely by a related group, targeted OPM's IT contractor KeyPoint Government Solutions in May 2014. Credentials from KeyPoint - which had network access to OPM systems - were used to expand access to the personnel database. This second actor obtained access to OPM's systems using legitimate KeyPoint credentials, making detection harder.
OPM's security team detected unusual data movement in April 2015 during an unrelated security product evaluation. Incident response revealed the two intrusions. The scope of the breach was initially reported as 4.2 million records; by July 2015, OPM acknowledged the actual number was 21.5 million - including 19.7 million applicants and 1.8 million family members.
The Fingerprints Database
A particularly sensitive element of the breach was the theft of 5.6 million fingerprint records. Physical biometrics cannot be changed; unlike passwords or even biographical data, fingerprints are permanent. The implications for covert operations are direct: any US intelligence officer who has ever been fingerprinted as part of a clearance application - and all of them have - has their biometrics in the Chinese government's possession.
Foreign intelligence services routinely fingerprint visitors. US officers operating under diplomatic cover who were biometrically enrolled in Chinese systems after the OPM breach could potentially be identified as intelligence personnel. The exact operational damage from the fingerprint theft has not been publicly disclosed, but counterintelligence assessments have described it as having "generational" effects on clandestine operations.
Attribution and Diplomatic Response
The Obama administration attributed the breach to Chinese intelligence in all but name - officials described China as the "leading suspect" in public statements while declining to make a formal public attribution. The decision not to formally attribute was deliberate: the US government did not want to establish a precedent of naming nation-states for intelligence operations, which could open the US to reciprocal accusations about its own intelligence activities.
China denied any involvement. Chinese foreign ministry spokesman Hong Lei called the accusation "irresponsible and unscientific."
In September 2015, President Obama and Chinese President Xi Jinping announced a cybersecurity agreement that included commitments not to conduct cyber-enabled intellectual property theft for commercial benefit. The agreement explicitly excluded government intelligence operations - the kind of espionage the OPM breach represented. The distinction between espionage (targeting government systems for strategic intelligence) and commercial IP theft (targeting private companies for economic advantage) became the administration's framework for the acceptable limits of state-sponsored hacking.
In 2017, the Department of Justice charged a Chinese national, Yucheng Wang, with involvement in providing cover for the OPM hackers through a company called Boyusec. Wang was not extradited and the case illustrated the limits of legal action against state-sponsored actors operating from non-extradition countries.
The Insider Connection: Harold Martin and Reality Winner
The OPM breach occurred in the same period as two significant insider threat cases at NSA. Harold Martin, a Booz Allen Hamilton contractor, was arrested in 2016 with 50 terabytes of classified material taken from NSA over twenty years. Reality Winner, another contractor, was arrested in 2017 for leaking a single NSA report on Russian election interference. Neither case was directly connected to the OPM breach, but they illustrated the broader landscape of insider risk and contractor security at US intelligence agencies in the period.
The OPM breach was an external operation; the insider cases were separate. But both reflected a common structural vulnerability: the US intelligence community's use of contractors created a wide population of individuals with clearances who were not subject to the same direct oversight as government employees, and who were potentially compromised through the OPM SF-86 data.
The Aftermath: OPM Shutdown and Reorganization
OPM Director Katherine Archuleta resigned in July 2015 under bipartisan pressure. The agency's acting director testified before Congress about the inadequate security practices that had allowed the breach - outdated systems, insufficient encryption, inadequate monitoring.
The National Background Investigations Bureau (NBIB) was subsequently created to take over the personnel security investigation process, and its IT functions were assigned to the Department of Defense. The reorganization was intended to apply stronger security standards to the clearance process data. In 2019, NBIB was consolidated into the Defense Counterintelligence and Security Agency (DCSA).
Congressional hearings on the OPM breach revealed that OPM had received persistent warnings about its cybersecurity vulnerabilities from the Inspector General for years before the breach - warnings that were not acted upon. The 2015 IG report described OPM's security as so inadequate that it recommended shutting down some systems entirely.
The long-term intelligence damage from the OPM breach is assessed as ongoing. The SF-86 data did not expire with the breach - it remains useful to Chinese intelligence indefinitely. The individuals whose records were stolen are still working, still subject to the vulnerabilities documented in their applications, still potentially identifiable through the fingerprint database. In the assessment of the counterintelligence community, the OPM breach was not an event but a condition.