There’s nothing quite like starting a new job as editor just as a huge story is breaking – a story with enough legs to perhaps become one of the biggest stories of the year.
But fair to say the breach that exposed millions of federal employee records held by the Office of Personnel Management is exactly that. And here I am, day two on the job, trying to make sense of the ramifications. What, if anything, have we as journalists yet to learn or share?
Then I had a conversation with a source of mine – one who just received a letter from the Homeland Security Department informing him that his own information submitted for a clearance may have been compromised. He asked that I not use his name, understandably wanting to limit the amount of exposure. But during that one phone call I very quickly learned what is perhaps getting lost amid all the reporting about the number and type of records breached and supposed connections to China.
“I have no way of knowing what was done with my information, nor do I know what will be done with my information,” he told me. Government’s willingness to pay for credit monitoring and repair? To him, that offers limited comfort. “Who do I trust? This might be something that will pop up in three years, or five years, or for all I know my information might be on a Russian hacking site being reproduced for credit cards as we speak.”
The reporter in me knows that his story actually introduces a lot of new questions, particularly since he was not even a federal employee, but a subcontractor to a large systems integrator supporting a DHS contract. If contractors were also exposed, does that tack on millions more to the number of individuals exposed? Little mention of contractors has been made up until now. It’s even unclear when DHS discovered his information was breached.
We’re trying to dig up that information as we speak.
But what we do know from his perspective is that this is about more than cyber vulnerabilities. It’s even about more than how many in all were hacked. That’s a statistic, albeit an elusive one. For federal managers and apparently the contractors that support their programs, it’s about personal security and the loss of confidence in the institutions that are supposed to keep both them and their information safe.
“DHS is supposed to be protecting us,” he added. “This is a letter I expect to get from Target or Home Depot. You understand when you go to a commercial entity it might happen, because well, they’re not DHS.”
The OPM hack risk that nobody is talking about




