How the OPM breach happened: a contractor's login and the two-factor rule nobody enforced
The biggest theft of U.S. government personnel secrets did not start with a clever exploit. It started with a contractor's stolen login, used on a network where two-factor sign-in was required on paper but not switched on.[1] This case file covers how intruders took background files on 21.5 million people and 5.6 million fingerprint records from the Office of Personnel Management, what it cost, and the control that would have stopped it.
What happened
The Office of Personnel Management, or OPM, is the federal government's human resources office. It also held the files from background investigations for security clearances: the long forms applicants fill out about their families, finances, past drug use and mental health.[1]
In March 2014, the federal cyber response team US-CERT told OPM that data was leaving its network. OPM watched that first intruder and then kicked it out in a planned cleanup on May 27, 2014.[1] But on May 7, 2014, nearly 3 weeks before that cleanup, a second intruder had already logged in using credentials belonging to an employee of KeyPoint, a contractor that did background checks for the government. The cleanup did not touch this second intruder.[1]
Over the next 11 months, the second intruder worked quietly. In July and August 2014 it took the background investigation files. In December 2014 it took 4.2 million federal personnel records. On March 26, 2015, it began taking fingerprint data.[1] OPM finally detected this intruder on April 15, 2015.[1]
How they got in
The key was a valid login. The second intruder signed in with a contractor employee's username and password, so to OPM's systems the session looked like normal remote work by someone who was allowed to be there.[1] Once inside, the intruder installed malware and set up web addresses that blended in with ordinary traffic to send stolen data out, one of them dressed up to look like an OPM training site.[1]
Federal agencies had long been required to use two-factor authentication for remote logins. That means a password plus a second proof, such as a government smart card, so a stolen password alone is not enough. OPM did not put that requirement into effect for remote access until early 2015, after the intruder had been inside for months.[1]
How it was caught
OPM spotted the second intruder in April 2015, nearly a year after it first logged in, and the fingerprint theft had been running for about 3 weeks by then.[1] After first disclosing the theft of personnel records, on July 9, 2015 it announced the larger loss: background investigation records on 21.5 million people, including current, former and prospective federal employees and some applicants' spouses or partners.[2] The fingerprint count, first put at 1.1 million, was later raised to 5.6 million.[3]
In September 2016, the House Oversight Committee published a report that blamed OPM leadership for ignoring years of warnings about its security. The hack was widely attributed in press coverage to Chinese government hackers, and the report's own title said the breach jeopardized national security for more than a generation.[1]
What it cost
OPM's director resigned on July 10, 2015, a day after the agency disclosed the 21.5 million figure.[4] Unlike a stolen card number, a fingerprint or a family history cannot be reissued, so the damage for the people in those files does not expire.
Federal employees and their unions sued. In October 2022 a federal judge gave final approval to a $63 million class action settlement for people harmed by the breach.[5]
The missing control
The missing control: enforced two-factor login for remote access. The rule already existed. It was simply not switched on for the doors the intruder used.
The House report was blunt on this point: had OPM enforced two-factor sign-in for remote access earlier, the intruder's stolen password would not have been enough to keep coming back.[1] Every step that followed, from the clearance files to the fingerprints, depended on that one valid login. A second factor would have turned a stolen password into a failed sign-in, and likely a warning sign.
There is a second lesson in the timeline. OPM cleaned out one intruder and declared the job done while another was already inside. After any break-in, assume there may be more than one, and check every account that can reach the network from outside.
What to do in your business
- Turn on two-factor for every remote login. Email, VPN, remote desktop, cloud admin panels and accounting software should all ask for a second proof, such as an app code or a security key.
- Check that the policy is actually on. Log in from outside as a test, or ask your IT provider for a report showing which accounts still sign in with only a password.
- Treat contractor accounts as your risk. Give vendors their own named accounts with two-factor, limited to what they need, and remove them the day the work ends.
- Keep your most sensitive files apart. Store HR files, ID copies and background checks in a separate location that ordinary logins cannot reach.
- After an incident, reset everything. Change all passwords, review every account with remote access, and keep watching for weeks, not days.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.