# Federal Government: 4 million Employees Data Hacked, at Risk

**URL:** <https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [June 4, 2015, 10:19pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666 "2015-06-04T22:19:14Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![ralph124c](https://avatars.discourse-cdn.com/v4/letter/r/8797f3/32.png) [@ralph124c](https://boards.straightdope.com/u/ralph124c)\
**Post date:** [June 5, 2015, 1:20pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/21 "2015-06-05T13:20:45Z")

</div>

So what if the hackers instruct the US government SS administration to list these people as “retired”-and starts sending them checks? This could get interesting-stay tuned.

---

<div class="post-metadata">

**Author:** ![Eva\_Luna](https://avatars.discourse-cdn.com/v4/letter/e/e495f1/32.png) [@Eva\_Luna](https://boards.straightdope.com/u/Eva_Luna)\
**Post date:** [June 5, 2015, 2:43pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/22 "2015-06-05T14:43:37Z")

</div>

> [@even\_sven](#):
>
> Right now, with few exceptions, no food is served anywhere. No office coffee pot. No lunch when hosting a special meeting. If your office wants a holiday gathering, you are free to have one on your own dime outside of work hours.
> 
> They even recently ruled that federal offices can’t stock plastic silverware in the lunch room.

That was the case even in 1994 when I left Federal employment. We all had to chip in for a fridge to store lunches, an office coffeepot and supplies, and a microwave, let alone silverware and napkins.

I can’t for the life of me figure out how I would have found out about this breach if I didn’t read the newspaper. I have moved several times since I left Federal employment, and I doubt they are going to put a whole lot of effort into looking for me.

I guess I will have to call OPM and see what the deal is. That ought to be fun - I’m sure they are slammed at the moment.

---

<div class="post-metadata">

**Author:** ![Laggard](https://avatars.discourse-cdn.com/v4/letter/l/9de053/32.png) [@Laggard](https://boards.straightdope.com/u/Laggard)\
**Post date:** [June 5, 2015, 2:51pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/23 "2015-06-05T14:51:40Z")

</div>

Leave it to someone to blame the President.

---

<div class="post-metadata">

**Author:** ![Tom\_Tildrum](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@Tom\_Tildrum](https://boards.straightdope.com/u/Tom_Tildrum)\
**Post date:** [June 5, 2015, 3:17pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/24 "2015-06-05T15:17:33Z")

</div>

> [@ralph124c](#):
>
> So what if the hackers instruct the US government SS administration to list these people as “retired”-and starts sending them checks? This could get interesting-stay tuned.

They don’t have that kind of access. This was a data theft like any other; they got a bunch of SSNs and can use the information to try to obtain credit in someone’s else’s name, or sell the SSNs to someone else who will do so.

My agency has informed us that OPM will provide 18 months of credit monitoring, and that if I was one of the compromised ones, I will be contacted directly by the monitoring firm (and probably a lot of other individuals and companies as well :rolleyes:).

---

<div class="post-metadata">

**Author:** ![Drunky\_Smurf](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/drunky_smurf/32/449_2.png) [@Drunky\_Smurf](https://boards.straightdope.com/u/Drunky_Smurf)\
**Post date:** [June 5, 2015, 3:55pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/25 "2015-06-05T15:55:37Z")

</div>

> [@samclem](#):
>
> So, who of the current candidates for President in 2016 would you suggest would fill the bill you have just posted?

Well certainly not Clinton who doesn’t understand that a Blackberry, an iPad and a phone are actually three separate devices and not just one.

---

<div class="post-metadata">

**Author:** ![Machine\_Elf](https://avatars.discourse-cdn.com/v4/letter/m/82dd89/32.png) [@Machine\_Elf](https://boards.straightdope.com/u/Machine_Elf)\
**Post date:** [June 5, 2015, 4:13pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/26 "2015-06-05T16:13:43Z")

</div>

> [@PastTense](#):
>
> Hacking incidents are so common, anymore. One wonders why the government doesn’t do more about it–but I suppose that would require updating ancient software.

This depends on your definition of “ancient.” Network security software does get updated on a regular basis, and the federal government, generally speaking, takes data security very seriously. Employees in my agency are required to take annual data security training, in which we are reminded not to fall for phishing attacks, not to open attachments/links from unknown senders, not to give passwords over the phone, and so on. We also have a phone number we can call if we suspect a network security breach, and it puts a whole team of network security folks into play. Some of the systems I interact with (e.g. the [Federal Acquisition Institute](http://www.fai.gov/drupal/)) require you to change your password every few months, and will lock you out if you guess your password wrong just a few times in a row.

As with any organization, there will be security holes, often created by someone not following official procedures, despite the government’s best efforts to train them. Hackers, poking and prodding the system 24/7, will eventually find those holes and exploit them, especially if the target is valuable enough (e.g. a database containing personal identifying information for millions of federal employees). Without knowing exactly what happened in this particular breach, it’s misguided to suggest that the government hasn’t exercised due diligence with regard to the security of its employees’ personal info.

---

<div class="post-metadata">

**Author:** ![davida03801](https://avatars.discourse-cdn.com/v4/letter/d/b5e925/32.png) [@davida03801](https://boards.straightdope.com/u/davida03801)\
**Post date:** [June 5, 2015, 5:09pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/27 "2015-06-05T17:09:13Z")

</div>

Really, anyone surprised ?

---

<div class="post-metadata">

**Author:** ![Eva\_Luna](https://avatars.discourse-cdn.com/v4/letter/e/e495f1/32.png) [@Eva\_Luna](https://boards.straightdope.com/u/Eva_Luna)\
**Post date:** [June 5, 2015, 5:47pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/28 "2015-06-05T17:47:16Z")

</div>

> [@Tom\_Tildrum](#):
>
> My agency has informed us that OPM will provide 18 months of credit monitoring, and that if I was one of the compromised ones, I will be contacted directly by the monitoring firm (and probably a lot of other individuals and companies as well :rolleyes:).

Any idea how they intend to hunt down former employees who aren’t currently on the radar because they have no reason to be, i.e. they are not receiving pensions, etc.?

---

<div class="post-metadata">

**Author:** ![Slash1972](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/slash1972/32/6461_2.png) [@Slash1972](https://boards.straightdope.com/u/Slash1972)\
**Post date:** [June 5, 2015, 6:18pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/29 "2015-06-05T18:18:42Z")

</div>

> [@Machine\_Elf](#):
>
> This depends on your definition of “ancient.” Network security software does get updated on a regular basis, and the federal government, generally speaking, takes data security very seriously. Employees in my agency are required to take annual data security training, in which we are reminded not to fall for phishing attacks, not to open attachments/links from unknown senders, not to give passwords over the phone, and so on. We also have a phone number we can call if we suspect a network security breach, and it puts a whole team of network security folks into play. Some of the systems I interact with (e.g. the [Federal Acquisition Institute](http://www.fai.gov/drupal/)) require you to change your password every few months, and will lock you out if you guess your password wrong just a few times in a row.

No offense, but the fact that you consider your list here “tak[ing] data security very seriously” is the reason why most federal agencies have piss poor security postures. The reason IS most people don’t care. Data, system, and network security hinder getting work done. For 90% of government employees, getting work done is their main concern. Anything else is just something that is bothersome. Annual training? Nobody likes doing that. Everyone just clicks “next” as fast as possible to get credit for taking it. Password gets locked out? Call a number and have them reset it, even though they have no idea who you are.

Must is made of the fact that hostile adversaries use “sophisticated attacks” and “super cyberweapons” when a simple email with a malicious attachment sent to an entire agency is almost 100% effective. Look at the contracts for network security. It is never 100% implementation of critical security patches or updates. If your network security is contracted out, they only care about conforming to the contract, not whether the network is secure or not. Further, the companies are not responsible nor liable for any attack that occurs. I expect to see more and more big data breeches in government networks.

---

<div class="post-metadata">

**Author:** ![BobLibDem](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/boblibdem/32/3149_2.png) [@BobLibDem](https://boards.straightdope.com/u/BobLibDem)\
**Post date:** [June 5, 2015, 6:30pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/30 "2015-06-05T18:30:21Z")

</div>

Why is this a problem in government networks specifically? You don’t think the employees at say Ford forget their passwords and have to call to get them reset? You don’t think bank employees zip through their security lessons as quickly as possible? All I’m seeing here is a lot of “GRRRR! I hate government! Government Bad! Government Always Bad!”

---

<div class="post-metadata">

**Author:** ![Tom\_Tildrum](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@Tom\_Tildrum](https://boards.straightdope.com/u/Tom_Tildrum)\
**Post date:** [June 5, 2015, 6:59pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/31 "2015-06-05T18:59:49Z")

</div>

> [@Eva\_Luna](#):
>
> Any idea how they intend to hunt down former employees who aren’t currently on the radar because they have no reason to be, i.e. they are not receiving pensions, etc.?

The memo we got did not say anything about former employees. I assume the federal government can find you if really wanted to, but I don’t know that they would give those tools to the credit monitor. It might not be a bad idea for you to call OPM or your former agency and update whatever address they may have for you.

---

<div class="post-metadata">

**Author:** ![Slash1972](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/slash1972/32/6461_2.png) [@Slash1972](https://boards.straightdope.com/u/Slash1972)\
**Post date:** [June 5, 2015, 7:15pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/32 "2015-06-05T19:15:39Z")

</div>

> [@BobLibDem](#):
>
> Why is this a problem in government networks specifically? You don’t think the employees at say Ford forget their passwords and have to call to get them reset? You don’t think bank employees zip through their security lessons as quickly as possible? All I’m seeing here is a lot of “GRRRR! I hate government! Government Bad! Government Always Bad!”

Oh, I’m not saying it is not a problem in non-government networks. But I don’t think people should be expecting government networks to be any more secure than commercial ones. Disclaimer, I’ve never worked on any commercial networks, only government ones.

---

<div class="post-metadata">

**Author:** ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)\
**Post date:** [June 5, 2015, 7:18pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/33 "2015-06-05T19:18:57Z")

</div>

> [@BobLibDem](#):
>
> The truth is, a determined superpower with a ton of money and skilled computer experts are going to be able to break into a lot of systems and wreak havoc.

Agreed. An attacker with enough time and resources will be able to break into a target almost 100% of the time. A sufficiently complex enterprise presents such a large attack surface that eventually the bad guys will find a weakness. This is not to say that organizations should just throw in the towel and take no steps to defend themselves. They need to continually raise the bar to make it as hard as possibly for the bad guys to break in, and hope that the bad guys run out of time, patience, and/or resources and move on to other targets. But, if your adversaries are a large number of people who are paid to clock in every day and bang on your systems, possibly with the resources of a nation behind them, they will get in.

I would hope that the President spends his time on issues at a higher level than the security controls implemented by one of the vast number of government agencies. Jesus, corporate CEOs for the most part can’t even be bothered to get involved with the nuts and bolts of information security, and they’re not walking around wondering if today is the day they’ll have to bomb North Korea.

---

<div class="post-metadata">

**Author:** ![DrDeth](https://avatars.discourse-cdn.com/v4/letter/d/b487fb/32.png) [@DrDeth](https://boards.straightdope.com/u/DrDeth)\
**Post date:** [June 5, 2015, 9:15pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/34 "2015-06-05T21:15:53Z")

</div>

Hey, anyone know how much of the National debt China owns? Let’s fine them that much.

---

<div class="post-metadata">

**Author:** ![gigi](https://avatars.discourse-cdn.com/v4/letter/g/a587f6/32.png) [@gigi](https://boards.straightdope.com/u/gigi)\
**Post date:** [June 5, 2015, 10:33pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/35 "2015-06-05T22:33:54Z")

</div>

> [@Snarky\_Kong](#):
>
> They’re not. China will be along to repo your kidney any time now.

I’ve always wanted to meet Jude Law.

---

<div class="post-metadata">

**Author:** ![adaher](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@adaher](https://boards.straightdope.com/u/adaher)\
**Post date:** [June 5, 2015, 11:58pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/36 "2015-06-05T23:58:16Z")

</div>

> [@BobLibDem](#):
>
> It’s a good thing that only the government is being targeted by hackers, it’d be a hell of a thing if hackers ever went after credit cards and banking data. Funny how the knives come out for Obama after we discover this sophisticated attack by a superpower but Bush got a pass after failing to act on intelligence that a ragtag group of terrorists was about to strike in late summer 2001.

THe knives haven’t come out. At all. In fact, I’m annoyed, not that Obama isn’t being raked over the coals, but that the government is going easy on itself when it came down like a ton of bricks on Target. This incident should be treated with just as much seriousness. Heads should roll.

> [@](#):
>
> The truth is, a determined superpower with a ton of money and skilled computer experts are going to be able to break into a lot of systems and wreak havoc. We may decry what the Chinese are doing but you can bet the US is doing or attempting to do the same to them. It’s just the latest variant in the ancient game of espionage. If you want to stop it, perhaps you should pressure your Congress to give the administration the funding to do something about it. Sitting back and saying “Haw, haw! Government can’t do shit! Seeeeeeeee! I tolllllllllllld you!” may be cathartic for some but a pretty childish response in reality.

So is assuming that when things go wrong it’s always because there wasn’t enough money. The government has 20%+ of GDP to spend. Any 536 morons(Congress+the President) should be able to meet most priorities with a $3 trillion pot.

---

<div class="post-metadata">

**Author:** ![Slash1972](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/slash1972/32/6461_2.png) [@Slash1972](https://boards.straightdope.com/u/Slash1972)\
**Post date:** [June 6, 2015, 12:46am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/37 "2015-06-06T00:46:37Z")

</div>

> [@adaher](#):
>
> THe knives haven’t come out. At all. In fact, I’m annoyed, not that Obama isn’t being raked over the coals, but that the government is going easy on itself when it came down like a ton of bricks on Target. This incident should be treated with just as much seriousness. Heads should roll.

Whose heads do you think should roll in the OPM data breech?

---

<div class="post-metadata">

**Author:** ![PastTense](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pasttense/32/14550_2.png) [@PastTense](https://boards.straightdope.com/u/PastTense)\
**Post date:** [June 6, 2015, 2:19am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/38 "2015-06-06T02:19:33Z")

</div>

> [@Bayard](#):
>
> Agreed. An attacker with enough time and resources will be able to break into a target almost 100% of the time. A sufficiently complex enterprise presents such a large attack surface that eventually the bad guys will find a weakness.

There’s no reason a lot of this stuff has to be on computers connected to the internet.

---

<div class="post-metadata">

**Author:** ![PastTense](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pasttense/32/14550_2.png) [@PastTense](https://boards.straightdope.com/u/PastTense)\
**Post date:** [June 6, 2015, 2:21am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/39 "2015-06-06T02:21:39Z")

</div>

> [@Eva\_Luna](#):
>
> Any idea how they intend to hunt down former employees who aren’t currently on the radar because they have no reason to be, i.e. they are not receiving pensions, etc.?

Tthe breach goes back to data from 1985.  
[http://www.reuters.com/article/2015/06/06/us-cybersecurity-usa-idUSKBN0OL1V320150606](http://www.reuters.com/article/2015/06/06/us-cybersecurity-usa-idUSKBN0OL1V320150606)

---

<div class="post-metadata">

**Author:** ![Eva\_Luna](https://avatars.discourse-cdn.com/v4/letter/e/e495f1/32.png) [@Eva\_Luna](https://boards.straightdope.com/u/Eva_Luna)\
**Post date:** [June 6, 2015, 2:36am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/40 "2015-06-06T02:36:02Z")

</div>

> [@Tom\_Tildrum](#):
>
> The memo we got did not say anything about former employees. I assume the federal government can find you if really wanted to, but I don’t know that they would give those tools to the credit monitor. It might not be a bad idea for you to call OPM or your former agency and update whatever address they may have for you.

I’ve seen news articles that mention former employee data was also affected. The last address the DOJ (my former agency) has for me is circa 1994. I think I will try to give them a call, but it may take some work to get through to the right person. If you have more specific contact info than just “call OPM,” would you please post or PM me?

ETA; whaddaya know, they’re actually [being kind of proactive,](http://www.opm.gov/news/latest-news/announcements/) though a letter sent to my last known postal address isn’t going to be so useful.

And yes, [the breach also affects former personnel.](http://www.opm.gov/news/latest-news/announcements/frequently-asked-questions/)

[Previous page](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666.md?page=1)

[Next page](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666.md?page=3)
