Cyberscoop Identity Theft Protection Services for OPM Breach Victims Set to Expire
Article Content
- •Identity theft protection for 22 million OPM breach victims is set to expire in September 2026.
- •Lawmakers are pushing for legislation to provide lifetime identity protection coverage.
- •A government watchdog report indicates OPM may have overpaid for identity theft services.
Ten years after the 2015 Office of Personnel Management (OPM) breach, identity theft protection services for approximately 22 million affected federal employees and their families are expiring. The breach, attributed to Chinese hackers, exposed sensitive personal information, including Social Security numbers. Lawmakers are advocating for the RECOVER PII Act to provide lifetime identity protection coverage, citing ongoing threats. The OPM has deemed extending the program too costly, despite low claims in recent years. A government watchdog report indicates OPM may have overpaid for these services, as claims rarely exceed a few thousand dollars. The expiration of services is set for the end of September 2026, prompting urgency among lawmakers and advocates for affected individuals.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track ID Experts in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…