OPM now reports 5.6M federal employees' fingerprints stolen in breach, up from 1.1M
OPM Now Admits 5.6m Feds' Fingerprints Were Stolen By Hackers — When hackers steal your password, you change it. When hackers steal your fingerprints, they've got an unchangeable credential that lets them spoof your identity for life.
Context & Ripple Effects
The fingerprint number is the latest in a string of upward revisions from OPM. In June, the federal worker union reported that Social Security Numbers and other data on all federal employees had been taken, and Wired reported the breach was far worse than first believed — exposed during a security company's sales demo. Days later came the second, larger hack affecting 21.5 million individuals, then reports that hackers grabbed potentially humiliating adjudication information on federal workers.
Each disclosure has made the damage assessment look worse than the last one, and this one follows the same arc: fingerprints stolen jumped from 1.1 million to 5.6 million. The breach has been linked by shared tooling to last year's Anthem intrusion tied to Chinese intelligence, giving hackers roughly a year to sift through personnel data before discovery.
First-order effects
- Roughly 5.6 million federal employees now carry a permanently compromised biometric credential that, unlike a password, cannot be reset — exposing them to identity spoofing for life.
- OPM's credibility takes another hit: the agency has now revised its own damage estimates repeatedly in a single summer, forcing it to defend why earlier counts understated the theft.
Second-order effects
- Agencies and contractors that rely on fingerprint-based background checks and facility access face reworking how they authenticate people whose prints are already in criminal hands — OPM already shut its background-check system down for weeks to patch vulnerabilities.
- The shared-tooling link to the Anthem breach keeps attribution pressure on China, raising the odds the incident feeds into broader US-China cybersecurity negotiations rather than staying an IT remediation story.
Third-order effects
- If biometric databases are treated as breach-inevitable, the structural fix points away from centralized stores of unchangeable identifiers toward revocable, template-based credential systems — with regulation likely to follow on what data agencies are permitted to retain at all.
- A pattern of repeated upward revisions trains Congress and the public to assume initial breach figures are floors, hardening expectations for mandatory disclosure timelines and independent forensics on federal systems.
The trend: Federal breach disclosures keep revising upward months after the fact, pushing government toward treating stored biometrics as liabilities rather than assets.