The 2014–2015 Office of Personnel Management intrusion, disclosed in June 2015, was one of the largest thefts of U.S. government data in history and exposed roughly 22.1 million records on federal employees, contractors, applicants, and their families. The attack consisted of two linked operations attributed to Chinese state-sponsored actors widely identified as the Jiangsu State Security Department, a subsidiary of China's Ministry of State Security; the first intrusion ("X1") was detected on March 20, 2014 after a third-party tip, while the second ("X2") began on May 7, 2014 when attackers posed as an employee of OPM subcontractor KeyPoint Government Solutions and was not discovered until April 15, 2015. Compromised material included the highly sensitive 127-page Standard Form 86 background-investigation questionnaires — covering family members, foreign contacts, and psychological history — along with 5.6 million sets of fingerprints, jeopardizing the cover of intelligence personnel. Attackers gained valid credentials likely through social engineering and used the PlugX backdoor and "Sakula" malware to establish persistence and escalate privileges. OPM Director Katherine Archuleta and CIO Donna Seymour resigned in the aftermath, and in 2017 Chinese national Yu Pingan was arrested at LAX for supplying the Sakula tool, ultimately pleading guilty and being sentenced to time served in February 2019. A class-action settlement in 2022 established a $63 million fund and the government procured roughly $416 million in long-term MyIDCare identity-protection services, while the breach became a defining cautionary tale about contractor access and legacy federal IT security.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

