Case file · OPM 2015

How the OPM breach happened: a contractor's login and the two-factor rule nobody enforced

Published 2026-09-29 · 4 min read · Missing control: Enforced two-factor for remote access

The biggest theft of U.S. government personnel secrets did not start with a clever exploit. It started with a contractor's stolen login, used on a network where two-factor sign-in was required on paper but not switched on.[1] This case file covers how intruders took background files on 21.5 million people and 5.6 million fingerprint records from the Office of Personnel Management, what it cost, and the control that would have stopped it.

What happened

The Office of Personnel Management, or OPM, is the federal government's human resources office. It also held the files from background investigations for security clearances: the long forms applicants fill out about their families, finances, past drug use and mental health.[1]

In March 2014, the federal cyber response team US-CERT told OPM that data was leaving its network. OPM watched that first intruder and then kicked it out in a planned cleanup on May 27, 2014.[1] But on May 7, 2014, nearly 3 weeks before that cleanup, a second intruder had already logged in using credentials belonging to an employee of KeyPoint, a contractor that did background checks for the government. The cleanup did not touch this second intruder.[1]

Over the next 11 months, the second intruder worked quietly. In July and August 2014 it took the background investigation files. In December 2014 it took 4.2 million federal personnel records. On March 26, 2015, it began taking fingerprint data.[1] OPM finally detected this intruder on April 15, 2015.[1]

How they got in

The key was a valid login. The second intruder signed in with a contractor employee's username and password, so to OPM's systems the session looked like normal remote work by someone who was allowed to be there.[1] Once inside, the intruder installed malware and set up web addresses that blended in with ordinary traffic to send stolen data out, one of them dressed up to look like an OPM training site.[1]

Federal agencies had long been required to use two-factor authentication for remote logins. That means a password plus a second proof, such as a government smart card, so a stolen password alone is not enough. OPM did not put that requirement into effect for remote access until early 2015, after the intruder had been inside for months.[1]

How it was caught

OPM spotted the second intruder in April 2015, nearly a year after it first logged in, and the fingerprint theft had been running for about 3 weeks by then.[1] After first disclosing the theft of personnel records, on July 9, 2015 it announced the larger loss: background investigation records on 21.5 million people, including current, former and prospective federal employees and some applicants' spouses or partners.[2] The fingerprint count, first put at 1.1 million, was later raised to 5.6 million.[3]

In September 2016, the House Oversight Committee published a report that blamed OPM leadership for ignoring years of warnings about its security. The hack was widely attributed in press coverage to Chinese government hackers, and the report's own title said the breach jeopardized national security for more than a generation.[1]

What it cost

OPM's director resigned on July 10, 2015, a day after the agency disclosed the 21.5 million figure.[4] Unlike a stolen card number, a fingerprint or a family history cannot be reissued, so the damage for the people in those files does not expire.

Federal employees and their unions sued. In October 2022 a federal judge gave final approval to a $63 million class action settlement for people harmed by the breach.[5]

The missing control

The missing control: enforced two-factor login for remote access. The rule already existed. It was simply not switched on for the doors the intruder used.

The House report was blunt on this point: had OPM enforced two-factor sign-in for remote access earlier, the intruder's stolen password would not have been enough to keep coming back.[1] Every step that followed, from the clearance files to the fingerprints, depended on that one valid login. A second factor would have turned a stolen password into a failed sign-in, and likely a warning sign.

There is a second lesson in the timeline. OPM cleaned out one intruder and declared the job done while another was already inside. After any break-in, assume there may be more than one, and check every account that can reach the network from outside.

What to do in your business

Watch the case
The breach that took 5.6 million fingerprintsDrops 2026-11-15
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Krebs on Security: Congressional report slams OPM on data breach
  2. IAPP: 21.5 million breached in second OPM hack
  3. CyberScoop: OPM stolen biometric data list grows by 4.5 million
  4. WYPR / NPR: OPM Director Archuleta resigns in wake of data breaches
  5. Nextgov: Judge finalized $63M OPM hack settlement