The OPM Breach: When Hackers Stole the Government's Background-Check Files
In 2015, state-linked hackers stole security-clearance records — including fingerprints — for 21.5 million people. It remains one of the most damaging government breaches ever disclosed.
Most breaches expose passwords or credit card numbers — things that can be changed. The 2015 breach of the US Office of Personnel Management exposed something that can’t: fingerprints, and the deeply personal details federal employees and contractors disclose during background investigations for security clearances.
What OPM actually is
OPM is the federal government’s HR department — it processes security clearance applications for federal employees, contractors, and military personnel. Those applications, called SF-86 forms, ask for an extraordinary amount of personal detail: past addresses, foreign contacts, financial history, mental health treatment, family members’ information.
What was stolen
Investigators attributed the intrusion to a state-sponsored group, believed to have had access to OPM’s networks for close to a year before discovery. The stolen data included background-investigation records for 21.5 million people, and separately, fingerprint data for 5.6 million of them — the first confirmed large-scale theft of biometric data from a government system.
Why this breach is different
A stolen password can be reset. A stolen credit card can be cancelled. Fingerprints and the contents of a security-clearance investigation — years of financial history, foreign contacts, personal admissions made in confidence to investigators — can’t be reissued. For people whose clearance files were stolen, intelligence officials warned the exposure could pose risks for years, including the risk of foreign intelligence services using the data to identify or pressure intelligence personnel.
What to actually do about it
- If you held a federal security clearance around 2015, OPM’s breach notifications and the identity-protection services offered afterward are worth taking seriously even years later — this wasn’t a “change your password” incident.
- Understand the broader lesson: government systems holding background-investigation data are high-value targets specifically because that data can’t be reissued, which is why agencies have since pushed for stronger encryption and access controls on this category of record.
- This incident is often cited as a turning point in how seriously the US government treats cybersecurity for systems holding sensitive personnel data — a useful piece of context whenever new federal cybersecurity policy references “lessons from OPM.”
Worried this affects you?
Check whether your email address has shown up in this breach — or any other — in seconds.
Run a free breach check →Related coverage
The Change Healthcare Breach: The Largest Healthcare Hack in US History
A ransomware attack on a single billing company froze prescriptions and payments across the entire US healthcare system for weeks. Here's what happened and who was affected.
HCA Healthcare: 11 Million Patient Records, One Exposed Storage Location
One of the largest hospital operators in the country lost patient data not through a sophisticated hack, but through a misconfigured external storage location. Here's what that means.