Skip to main content

Three-quarters of U.S. OPM hack victims still in dark

Your highly dysfunctional federal government at its very worst as shown below. And to think, this massive hack involved all your clearance data and your biometric data, too. And the data for your relatives. Nothing but silence from the OPM, though, with no help for those who have been compromised. Imagine if some business was hacked and responded this slowly to the compromised data of their customers.


*** Three-quarters of U.S. OPM hack victims still in dark - Reuters, Nov 3rd, 2015 ***

WASHINGTON (Reuters) - Fewer than a quarter of 21 million federal workers hit by a major computer hack have been officially told that their personal information was compromised, six months after the breach was detected, a U.S. government official said on Tuesday.

About 5 million notifications about the hack have been sent out so far, a spokesperson for the U.S. Office of Personnel Management (OPM) told Reuters in an email.

The slowness of the notification process underscores Washington's struggles in dealing with its computer vulnerabilities, a growing problem that the Obama administration has been trying to address.

After it fell victim to two successive cyber attacks, both begun in 2014 and revealed earlier this year, OPM was roundly criticized by lawmakers for its response.

OPM had no immediate additional comment on the matter on Tuesday, or on its expected notification timetable ahead.

Comments

GreggS said…
This administration has moved at breakneck speed to enact regulations via executive order on subjects near and dear to the president. But the security of employee data clearly does not matter to him so even the most basic of tasks like notification have failed to have be done.

Hopefully, the electorate will have learned that no matter the pretty message, we are never in need of a dictator that rules by personal fiat. The traditional system of checks and balances is cumbersome, but it protects us from abuses like this OPM mess.
Anonymous said…
You can contact OPM by phone and find out if you are a hacking victim, you don't have to wait for them to contact you.
GreggS said…
Yes I could. No I don't. No I should not have to.

The law specifies the protocol that is supposed to be followed. OPM is clearly dragging it's feet on this matter.
Anonymous said…
If you think there is anything you would do differently if you knew you had been affected, then logic would suggest you should do everything you can to find out without waiting for OPM. If you think there is nothing you could or should be doing differently then your attitude makes a kind of sense, I guess.
Anonymous said…
What should be happening is the same thing that happens when any major US business gets hacked:

(A) The company immediately informs those affected by mailing them a letter detailing what was compromised

(B) The company then arranges for the customers to get a free ID protection security service for a year or two

Target did this with their hack last year, T-Mobile did this with their recent hack, etc. What has our federal government done after almost a year of knowing about this massive hack of IDs, confidential medical info and biometric info? Absolutely nothing. That is inexcusable.

GreggS said…
Exactly as 9:38 said.

Some years back there was a breach at the Veterans Administration. I was notified by mail very shortly afterwards.

Why can't OPM behave the same way? I'd like to think they were not ordered to drag their feet, but what evidence is there to the contrary?
CF said…
OPM isn't better or worse at handling personal data than universities or companies. They all basically treat your data like your safety; they'll make some effort to protect you (and then spend twice as much energy convincing everyone how much they protect you), but in the end nobody cares but you.

The obvious difference is that since the personal data that OPM has is a tiny bit more valuable than that housed by most companies and universities, it not only attracts online bank thieves, but also ID thieves, terrorists, and oh yeah, ENTIRE FREAKING SOVEREIGN NATIONS who would LOVE to know anything that OPM has on you.

"(B) The company then arranges for the customers to get a free ID protection security service for a year or two"

You mean those worthless services that every breached .com .gov .edu buys in bulk for a pittance? As usual, it's mostly just feel-good back patting and publicity. At least it instills a false sense of security...
GreggS said…
11:55 hit the nail on the head. Absolutely true.

But even if a bad joke, the response is not there from OPM.

After spending an entire career implementing regulations detailing safeguarding information it irks me greatly to see someone else not only acting recklessly with sensitive data, but not facing any corrective action after one or more major infractions.
Anonymous said…
4:40 PM is irked (and justifiably so) that no one is facing corrective action at OPM. Well the head of OPM did resign so maybe the administration figures that's enough. If you had the chance to see her testimony at the congressional hearing it made you cringe knowing that such incompetence was running the organization.
GreggS said…
Incompetence hires more incompetence. The person(s) that oversee OPM should also be punished. And a review of security procedures done immediately to secure those servers so that further incidents do not occur.
Anonymous said…
Two people I know have been forwarded OPM letters from their parents' addresses. OPM is apparently using the information from when they FIRST applied for a clearance, even though it was ~20 years ago and they've filed multiple rounds of paperwork since.
GreggS said…
Wait... the folks overseeing my security clearance, the ones who would reject a form if it had pencil marks on it, can't look up my current address?!!!

Sigh.......
CF said…
7:37's experience is not uncommon.

Evil Echo is right to be frustrated. How exactly does OPM lack the ability to to find people (who have given them comprehensive life histories and unprecedented personal access) to tell them directly that their data was stolen during a breech that may have had state ties?

Clearly we need to step up electronic domestic surveillance to prevent such problems in the future .
Anonymous said…
Shouldn't be too long before everyone with a high level clearance is required to be "chipped" just to keep their job.

Cleared federal workers will be the first large group to undergo continuous tracking by our government.
GreggS said…
Given the inability to maintain what resources are currently allocated to them, how could I begin to trust the US government with chip implants?

Chips represent the ultimate loss of privacy. I'm sorry, but that is a bridge too far for me.

Popular posts from this blog

Plutonium Shots on NIF.

Tri-Valley Cares needs to be on this if they aren't already. We need to make sure that NNSA and LLNL does not make good on promises to pursue such stupid ideas as doing Plutonium experiments on NIF. The stupidity arises from the fact that a huge population is placed at risk in the short and long term. Why do this kind of experiment in a heavily populated area? Only a moron would push that kind of imbecile area. Do it somewhere else in the god forsaken hills of Los Alamos. Why should the communities in the Bay Area be subjected to such increased risk just because the lab's NIF has failed twice and is trying the Hail Mary pass of doing an SNM experiment just to justify their existence? Those Laser EoS techniques and the people analyzing the raw data are all just BAD anyways. You know what comes next after they do the experiment. They'll figure out that they need larger samples. More risk for the local population. Stop this imbecilic pursuit. They wan...

Trump is to gut the labs.

The budget has a 20% decrease to DOE office of science, 20% cut to NIH. NASA also gets a cut. This will  have a huge negative effect on the lab. Crazy, juts crazy. He also wants to cut NEA and PBS, this may not seem like  a big deal but they get very little money and do great things.

LLNL un-diversity

Actual post from Dec. 15 from one of the streams. This is a real topic. As far as promoting women and minorities even if their qualifications are not as good as the white male scientists, I am all for it. We need diversity at the lab and if that is what it takes, so be it.  Quit your whining. Look around the lab, what do you see? White male geezers. How many African Americans do you see at the lab? Virtually none. LLNL is one of the MOST undiverse places you will see. Face it folks, LLNL is an institution of white male privilege and they don't want to give up their privileged positions. California, a state of majority Hispanics has the "crown jewel" LLNL nestled in the middle of it with very FEW Hispanics at all!