ZeroHour
CyberScooppublished ()ingested @Bing_Chris

Lawmakers demand answers in wake of strange OPM identity fraud lawsuit

criticalPhishing & fraud exploited in the wildimportance 60
Full article829 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Virginia lawmakers are especially interested in learning how the defendants acquired the data.

OPM identity fraud
(Wikicommons)

With mystery swirling around an identity theft case where prosecutors have claimed the perpetrators used personal information included in the Office of Personnel Management breach, two lawmakers are pushing the government for more information.

A pair of letters sent this week by Sen. Mark Warner, D-Va., and Rep. Gerry Connolly, D-Va., to the heads of the Department of Justice and OPM issues a number of questions about the alleged identity fraud charges. The Virginia lawmakers are especially interested in learning how the defendants acquired the data.

On June 18, the Eastern District of Virginia announced that a Maryland woman had pleaded guilty to identity theft charges. That press release initially said the data used in that crime was from the OPM breach. On June 21, the district issued a correction to their press release, stripping any mention of the breach.

A comparison of the press releases issued by the U.S. Eastern District of Virginia. On the left, the press release from June 18. On the right, the amended version from June 21.

Virginia is home to the single largest population of federal workers and government contractors. Data stolen from OPM carried highly sensitive personal identifiable information, including social security numbers and medical records. Fears that the stolen data could be used by criminals has been looming for years.

The widely assumed notion is that OPM breach was carried out by a Chinese government-linked hacking group that was looking for counterintelligence material. While never publicly attributed to any group, the breach was not believed to be carried out by financially motivated actors.

The latest revelation challenges that narrative and simultaneously helps various civil lawsuits still pending against the government for the breach.

It remains possible that the defendant in this case used stolen data that also existed in OPM’s database, but was taken entirely different source, such as a breached financial institution.

Since the DOJ announcement, current and former government officials affected by the breach have questioned if they, too, are now at risk of having their identities stolen.

Multiple attempts to contact the defendant’s lawyer went unanswered.

Connolly told CyberScoop Wednesday that if the alleged fraudsters really did use data stolen by hackers during the 2015 OPM breach, it would be “hard to believe” that there weren’t more victims of fraud using that data.

But regardless of what emerges in the fraud case, Connolly said that there was a continued and urgent need to protect the OPM breach victims.

“I am very alarmed,” he said. “What additional measures are we taking to protect against that [fraud]?”

You can read the letters from Connolly and Warner below.

Sean Lyngaas contributed to this report.

[documentcloud url=”http://www.documentcloud.org/documents/4560208-Letter-to-DOJ-and-OPM.html” responsive=true]

[documentcloud url=”http://www.documentcloud.org/documents/4562291-2018-06-26-Gec-Letter-to-Doj-Opm-Data-Breach-Case.html” responsive=true]

More Scoops

Del. Eleanor Holmes Norton, D-D.C., speaks at a press conference outside the U.S. Capitol on March 10, 2024. (Photo by Kayla Bartkowski/Getty Images)

Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming

Sen. Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., hope to make the services permanent before they end next month.

Billionaire Elon Musk, then-head of the Department of Government Efficiency (DOGE), holds a chainsaw as he speaks at the annual Conservative Political Action Conference (CPAC) at the Gaylord National Resort Convention Center at National Harbor in Oxon Hill, Maryland, on Feb. 20, 2025. (Photo by SAUL LOEB / AFP)

Dem report concludes Department of Government Efficiency violates cybersecurity, privacy rules

Federal workers and their supporters gather outside OPM on Feb. 4, 2025, in Washington, D.C., to protest Elon Musk and DOGE’s takeover of federal systems. (Scoop News Group photo by Madison Alder)

Lawmakers fear Elon Musk, DOGE not adhering to privacy rules

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/opm-identity-fraud-mark-warner-gerry-connolly/