OPM hack: 21 million people's sensitive details stolen in biggest cyberattack in US history
‘It's a treasure trove of information about everybody who has worked for, tried to work for, or works for the United States government,’ the FBI director said
Hackers stole the most sensitive information of 21 million people in the US, it has been revealed, and nobody will say who did it.
An already huge breach of the US government’s computer systems was much bigger than previously thought, the Obama administration has revealed.
The scope of the data breach, believed to be the biggest in US history, has grown dramatically since the government first said earlier this year that hackers had gotten into the Office of Personnel Management's (OPM) personnel database and stolen records for about 4.2 million people.
Since then, the administration has acknowledged a second, related breach of the systems housing private data that individuals submit during background investigations to obtain security clearances.
That second attack affected more than 19 million people who applied for clearances, as well as nearly two million of their spouses, housemates and others who never applied for security clearances, the administration said.
Among the data the hackers stole was criminal, financial, health, employment and residency histories, as well as information about their families and acquaintances.
The new revelations drew indignation from members of Congress who have said the administration has not done enough to protect personal data in their systems, as well as calls for OPM director Katherine Archuleta and her top deputies to resign.
Yet Ms Archuleta insisted she would not step down.
In a conference call with reporters, Ms Archuleta said the hackers also got hold of the user names and passwords that prospective employees used to fill out their background investigation forms, as well as the contents of interviews conducted as part of those inquiries.
Yet the government insisted there were no indications that the hackers have used the data they stole.
Numerous US lawmakers have said China was behind the attack. But Michael Daniel, President Barack Obama's cybersecurity co-ordinator, said the government was not yet ready to say who was responsible.
Officials have acknowledged that the same party was responsible for both of the breaches, which took place in 2014 and early 2015. Investigators previously said that the US government was increasingly confident that China's government, and not criminal hackers, was responsible for the extraordinary theft of personal information.
China has publicly denied involvement in the break-in.
Yesterday, during a round-table discussion with reporters, FBI director James Comey described the scope of the OPM breach as "huge".
"It's a treasure trove of information about everybody who has worked for, tried to work for, or works for the United States government," he said.
The administration says it has stepped up its cybersecurity efforts by proposing new legislation, urging private industry to share more information about attacks and examining how the government conducts sensitive background investigations.
Additional reporting by Press Association
Comments
Share your thoughts and debate the big issues
Please be respectful when making a comment and adhere to our Community Guidelines.
You can find our Community Guidelines in full here.
- -1) ? 'active' : ''">
Newest first
- -1) ? 'active' : ''">
Oldest first
- -1) ? 'active' : ''">
Most liked
{{/moreThanOne}}Please be respectful when making a comment and adhere to our Community Guidelines.
You can find our Community Guidelines in full here.
- -1) ? 'active' : ''">
Newest first
- -1) ? 'active' : ''">
Oldest first
- -1) ? 'active' : ''">
Most liked
{{/moreThanOne_p}}Follow comments
Vote
Report Comment
Subscribe to Independent Premium to debate the big issues
Want to discuss real-world problems, be involved in the most engaging discussions and hear from the journalists? Start your Independent Premium subscription today.
Already registered? Log inReport Comment
Delete Comment
About The Independent commenting
Independent Premium Comments can be posted by members of our membership scheme, Independent Premium. It allows our most engaged readers to debate the big issues, share their own experiences, discuss real-world solutions, and more. Our journalists will try to respond by joining the threads when they can to create a true meeting of independent Premium. The most insightful comments on all subjects will be published daily in dedicated articles. You can also choose to be emailed when someone replies to your comment.
The existing Open Comments threads will continue to exist for those who do not subscribe to Independent Premium. Due to the sheer scale of this comment community, we are not able to give each post the same level of attention, but we have preserved this area in the interests of open debate. Please continue to respect all commenters and create constructive debates.