TechNewsReel
Live

Lawmakers Seek Lifetime ID Protection for 22.1 Million OPM Breach Victims

The RECOVER PII Act aims to make identity monitoring permanent as benefits from the 2015 Office of Personnel Management data breaches expire.

TechNewsReel Newsroom · August 10, 2026

Free identity theft protection for approximately 22.1 million people affected by the 2015 Office of Personnel Management (OPM) data breaches is expiring on a rolling basis. The expiration marks the end of a decade-long government effort to mitigate one of the most significant personnel data losses in U.S. history.

The government-funded program, administered through MyIDCare, is scheduled to terminate entirely by September 30, 2026. This monitoring service was mandated by the Consolidated Appropriations Act of 2017, which provided affected individuals with 10 years of identity monitoring and a $5 million insurance floor. In response to the looming deadline, Senator Mark Warner and Delegate Eleanor Holmes Norton have introduced the RECOVER PII Act, a legislative effort to convert this temporary protection into lifetime coverage.

The Legacy of the 2015 Breaches

The 2015 OPM breaches compromised the records of roughly 22.1 million individuals. The stolen data was exceptionally sensitive, including Social Security numbers, fingerprints, and detailed security clearance records. The incident involved two distinct breaches: one affecting 4.2 million personnel records and a second, more expansive breach that exposed background-investigation records for 21.5 million people. These attacks were linked to actors associated with the Chinese government.

While OPM initially offered only three years of protection following the discovery of the breaches, Congress intervened to expand the window to 10 years. However, OPM has since declined to extend the contract further, citing high costs and a decline in the volume of claims filed in recent years.

National Security Implications

Lawmakers argue that the nature of the stolen personally identifiable information (PII) makes the expiration of benefits a critical risk. Unlike passwords or credit card numbers, fingerprints and security clearance data do not lose value over time and cannot be changed.

There is a significant national security concern regarding the trajectory of the affected individuals. Many who held junior roles in 2015 may now occupy highly sensitive positions within the federal government. This makes decade-old stolen data highly valuable to foreign intelligence services for the purposes of targeting, blackmail, or interference. Senator Mark Warner emphasized the government's responsibility, stating that current and former public servants "should not be abandoned to bear the risks of the federal government’s failure to protect their sensitive information."

Future Outlook

The fate of the affected millions now rests on the passage of the RECOVER PII Act. If successful, the bill would ensure that those whose most intimate biometric and professional data were compromised remain protected for life. Observers will be watching whether Congress views the declining claim volume as a sign that the risk has passed, or if the permanent nature of biometric theft necessitates a permanent government solution.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.