Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
breach-disclosure-notificationgovernment-diplomatic-threatmass-credential-exposurestate-sponsored-espionage

Identity Protection for OPM Breach Victims Expires After 10-Year Federal Program

Updated 1mo agoFirst seen May 5, 20262 sources

Identity theft protection services for victims of the 2015 Office of Personnel Management breach are beginning to expire 10 years after enrollment, closing a major federal remediation effort tied to one of the most damaging U.S. government cyber intrusions. The breach affected more than 22.1 million people, including federal employees, security-clearance applicants, and family members, across two incidents involving personnel records and background-investigation data; the intrusions were widely assessed as linked to China. OPM first offered three years of coverage, then expanded benefits to 10 years under the Consolidated Appropriations Act of 2017, with contracts worth hundreds of millions of dollars awarded to ID Experts, now IDX.

OPM said it considered extending the program but decided against it because of high costs and low recent claims, while the Government Accountability Office had argued the coverage was excessive and could distort the market. A 2022 class-action settlement set aside $63 million for hardship claims, but only about $4.8 million was paid to just over 5,000 people before the remaining funds were returned to the U.S. Treasury. The expiration has drawn mixed reactions from affected individuals, with some warning that the stolen data could create lifelong risk, while others say a decade of support was sufficient; some recipients also reported follow-up marketing from IDX encouraging them to buy continued coverage on their own.

Share:
Identity Protection for OPM Breach Victims Expires After 10-Year Federal Program
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
May 5, 20262mo ago

Identity protection benefits for OPM breach victims begin expiring

Ten years after enrollment, identity theft protection services for people affected by the 2015 OPM breach began to expire in 2026, ending a major long-term federal response to the incident. Some recipients reported surprise at the expiration, while IDX followed up with marketing emails offering paid continued coverage.

OPM declines to extend identity protection beyond 10 years

Before the 10-year coverage period ended, OPM said it considered extending the identity protection program but decided against doing so because of high costs and low recent claims. Critics, including the Government Accountability Office and some lawmakers, had debated the scope and duration of the coverage.

Oct 26, 20224y ago

Class action settlement creates $63 million hardship fund

A 2022 class action settlement made $63 million available for hardship claims by people affected by the OPM breach. According to later reporting, only about $4.8 million was ultimately paid to just over 5,000 individuals, with the remainder returned to the U.S. Treasury.

May 5, 20179y ago

Congress expands OPM breach coverage to 10 years

Under the Consolidated Appropriations Act of 2017, Congress extended identity protection coverage for OPM breach victims from three years to 10 years and increased associated insurance coverage. This significantly expanded the federal government's long-term remediation effort.

Sep 1, 201511y ago

OPM begins offering three years of identity protection to victims

Following the breach, OPM provided affected individuals with three years of identity theft protection and related remediation services as part of its initial response. The services were delivered through contracts with ID Experts, later renamed IDX.

Jul 9, 201511y ago

OPM breach exposes records of more than 22.1 million people

In 2015, two Office of Personnel Management-related breaches exposed federal personnel records and security-clearance applicant data affecting more than 22.1 million people, including employees, applicants, and family members. The intrusion was widely assessed as linked to China.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

2 LINKEDOpen in app
Organizations
2 linked
IDXGovernment Executive
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Identity Protection for OPM Breach Victims Expires After 10-Year Federal Program | Mallory