EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/espionage-operation/opm-data-breach
271/430

File EL-0160CriticalResolvedEspionage Operation / Personnel Data Theft

OPM Data Breach

Also filed as OPM Personnel File Theft · Deep Panda Breach

The OPM Data Breach was a massive espionage operation involving the theft of personnel files and security clearance background investigation data for millions of U.S. government employees. The stolen data included highly sensitive personal details, such as fingerprints, polygraph results, and detailed personal histories. This breach represented one of the most significant intelligence leaks in modern US history.

  • #opm
  • #china
  • #apt19
  • #deep-panda
  • #security-clearance
  • #pii
  • #government-espionage
Notoriety9/10
Event
4 Jun 2015
Disclosed
4 Jun 2015
Target
Office of Personnel Management (OPM)
Actor
Deep Panda
Scale
21.5M records
Status
Resolved

01Summary

The attackers, attributed to Chinese state-sponsored actors (Deep Panda/APT19), infiltrated the Office of Personnel Management (OPM) over an extended period, culminating in the theft of records belonging to millions of current and former federal employees. The compromised data included the Standard Form 86 (SF-86), a comprehensive questionnaire used to vet individuals seeking security clearances. The sheer volume and depth of the stolen information—including fingerprints, drug use history, mental health records, and family details—provided foreign intelligence services with an unprecedented level of insight into the reliability and personal lives of US government workers. The breach highlighted critical vulnerabilities in federal data handling and security protocols, leading to massive policy and regulatory overhauls within the US government.

02Background

The OPM is the primary agency responsible for managing federal employee records and conducting background investigations for security clearances. Due to the critical nature of the information it holds—which determines who can access sensitive government systems—it became a prime target for foreign intelligence services. The breach exploited systemic weaknesses in data storage and network segmentation within the federal government's IT infrastructure.

03Key revelations

  1. 01The theft of the Standard Form 86 (SF-86), which contains deeply personal information used to verify an individual's reliability for government work.
  2. 02The exfiltration of 5.6 million sets of fingerprints, a permanent biometric identifier.
  3. 03The compromise of polygraph test results and detailed personal histories, including drug use and mental health records.

04Technical analysis

The attack vector was believed to involve sophisticated spear-phishing or supply chain compromise, allowing the attackers to gain initial access and establish persistent footholds. The threat actors utilized custom malware and advanced techniques to exfiltrate massive datasets over time. The data was systematically collected, including biometric data (fingerprints) and highly sensitive psychological and personal records, indicating a long-term, patient intelligence-gathering campaign rather than a quick smash-and-grab.

Attack vector
Unknown (Likely spear-phishing or supply chain compromise)
Attack method
Persistent Espionage and Data Exfiltration
Lateral movement
Internal network pivoting and credential harvesting
Persistence
Backdoors and compromised accounts
Exfiltration
Bulk data transfer over encrypted channels
Tool / malware
Unknown (Custom malware used for exfiltration)
Malware type
Stealer / Backdoor

MITRE ATT&CK techniques

  • T1022
  • T1078

05Threat actor

Deep Panda (APT19) is a sophisticated, state-sponsored threat group widely attributed to the Chinese Ministry of State Security (MSS). Their operations are characterized by long dwell times, targeted espionage, and the theft of high-value intellectual property and personal data from foreign governments.

Aliases

  • APT19
  • China MSS
  • Chinese State Actors

APT designations

  • APT19
  • China APT

MITRE groups

  • T1078
  • T1566.001

Attribution sources

  • Mandiant
  • FireEye
  • US Government Reports

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • Fingerprints
  • Personal Identifying Information (PII)
  • Financial Records
  • Health Records
  • Security Clearance Data
  • Polygraph Results
  • Family Details

Notable documents

  • Standard Form 86 (SF-86)

08Financial damage

Damage is primarily measured in loss of national security and trust, not direct financial cost.

09Timeline

  1. 2013-01-01Start of initial infiltration period by Deep Panda/APT19.
  2. 2015-06-04Date of public disclosure and confirmation of the massive data theft.

10Key figures

  • US Government EmployeesVictims · OPMAmericanLoss of privacy and security risk

11On the record

This was one of the most damaging intelligence breaches in US history.

Security Analysts, Describing the scale and impact of the OPM data theft.

12Reaction and fallout

Public reaction

The public reaction was characterized by widespread alarm regarding the vulnerability of personal data held by federal agencies. It fueled public debate over the necessity and security of centralized government data repositories.

Political impact

The breach led to significant political scrutiny of the US federal government's cybersecurity posture and data handling practices. It contributed to calls for major legislative reforms regarding data privacy and government IT modernization.

Geopolitical consequences

The incident was cited by Western governments as evidence of China's sustained, long-term efforts to acquire sensitive intelligence on US personnel and national security infrastructure.

13Legal

While no specific criminal charges were filed against foreign actors, the incident triggered internal government reviews, leading to increased funding and mandates for federal cybersecurity improvements and data compartmentalization.

14Aftermath

Policy changes

  • Increased federal requirements for data minimization and compartmentalization of sensitive PII.
  • Mandates for enhanced biometric data security protocols.

Regulatory changes

  • Strengthening of federal IT security standards (e.g., FISMA compliance enhancements).

Security improvements

  • Implementation of Zero Trust Architecture principles within federal networks.
  • Enhanced encryption and access controls for biometric and PII databases.

15Significance and legacy

Significance

The OPM breach is historically significant because it demonstrated the capability of a sophisticated, well-resourced nation-state actor to conduct a long-term, deep-dive intelligence operation against the core personnel records of a major global power. It set a precedent for treating federal employee data as a critical national security asset, comparable to military secrets.

Legacy

The breach permanently altered the conversation around digital privacy in the public sector. It accelerated the push for modernizing aging federal IT systems and forced a global reckoning regarding the risks associated with centralized, highly sensitive personal data repositories.

16Disclosure and media

Authentication
Government/Security Agency Confirmation

Media partners

  • The New York Times
  • The Washington Post
  • BBC News

Publishing organisations

  • Major Investigative News Outlets

17Related files

Related events

  • NSA Surveillance Disclosures
  • Equifax Breach

18Field notes

  1. 01The Standard Form 86 (SF-86) is a highly detailed document, sometimes exceeding 100 pages, designed to capture every aspect of an applicant's life history.
  2. 02The breach highlighted that even highly secure government systems can be vulnerable to persistent, low-and-slow data exfiltration over years.

19Resolution

The OPM was forced to undergo massive, multi-year IT modernization and security overhaul programs to mitigate the vulnerabilities exploited by the attackers.

20Sources

Official documents

  • US Government Cybersecurity Reports (Post-2015)

References

  1. [1]Mandiant Threat Intelligence Reports
  2. [2]The New York Times Investigative Reporting
Fact sheetEL-0160

Dates

Event
4 Jun 2015
Started
1 Jan 2013
Ended
4 Jun 2015
Discovered
4 Jun 2015
Disclosed
4 Jun 2015
Ongoing
No

Target

Organisation
U.S. Office of Personnel Management
Type
Government
Sector
Federal Government
Country
United States
Gov. level
Federal

Actor

Name
Deep Panda
Type
Nation-State Actor
Nationality
Chinese
Nation-state
China
Affiliation
Ministry of State Security (MSS)
Motivation
Acquisition of sensitive US government personnel data for intelligence gathering and strategic advantage.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Records
21,500,000
Volume
Millions of records (estimated 4.2 million personnel files)
Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.