ZeroHour
CyberScooppublished ()ingested @snlyngaas

DOJ regrets the error on OPM

criticalData breach exploited in the wildimportance 60
Tagsbreach
Full article762 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

DOJ as apologized for confusion over its announcement last month that a fraudster used information stolen in the infamous 2015 OPM data breach.

Sen. Mark Warner at FedTalks in June 2013. (FedScoop)

The Department of Justice has apologized for confusion over its announcement last month that a fraudster used information stolen in the infamous 2015 Office of Personnel Management breach — an episode that confounded lawmakers and ran counter to publicly available information on the breach.

The confusion began after DOJ announced on June 18 that a Maryland woman had pleaded guilty to using stolen OPM data to get car and personal loans. The public assumption had been – and still is – that Chinese hackers had stolen the data for espionage purposes.

But DOJ now says that it hasn’t yet determined whether the woman and her accomplice got the data from the OPM breach or somewhere else.

After an internal review, the U.S. Attorney’s Office for the Eastern District of Virginia appended a statement to its press release saying that “numerous victims” of the fraud self-identified as victims of the OPM breach. “The government continues to investigate the ultimate source of the [personally identifiable information] used by the defendants” and how it was obtained, the statement said.

Puzzled how the data might have ended up in American scammers’ hands, Sen. Mark Warner, D-Va., and Rep. Gerry Connolly, D-Va., wrote to DOJ and OPM demanding answers.

In a response Monday to Warner, Assistant Attorney General Stephen E. Boyd said the investigation has not yet determined exactly how the victims’ data was exposed and “whether it can, in fact, be sourced directly to the OPM data breach.”

“Because the victims in this case had other things in common in terms of employment and location, it is possible that their data came from another common source,” Boyd added.

“Regrettably,” Boyd continued, the original DOJ press release “implied a premature conclusion that the exclusive and known source of the stolen identities used in the [fraud case] was the OPM data breach.”

“We apologize for the confusion,” he wrote.

In a statement to CyberScoop, a spokesperson for Warner said the senator is “pleased that DOJ has clarified the initial announcement, which led to significant, and apparently unneeded, anxiety for millions of victims of the OPM breach.”

You can read the full letter from Boyd to Warner below.

[documentcloud url=”http://www.documentcloud.org/documents/4594013-2018-7-9-Stole-Identification-Langley-Federal.html” responsive=true height=500]

More Scoops

Del. Eleanor Holmes Norton, D-D.C., speaks at a press conference outside the U.S. Capitol on March 10, 2024. (Photo by Kayla Bartkowski/Getty Images)

Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming

Sen. Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., hope to make the services permanent before they end next month.

Federal workers and their supporters gather outside OPM on Feb. 4, 2025, in Washington, D.C., to protest Elon Musk and DOGE’s takeover of federal systems. (Scoop News Group photo by Madison Alder)

Lawmakers fear Elon Musk, DOGE not adhering to privacy rules

threat landscape hearing
Sens. Gary Peters, D-Mich., and Rob Portman, R-Ohio, speak to Secretary of Homeland Security Alejandro Mayorkas, right, after a Senate Homeland Security and Governmental Affairs hearing Sept. 21, 2021 in Washington, D.C. (Photo by Greg Nash – Pool/Getty Images)

The long, bumpy road to cyber incident reporting legislation — and the one still ahead

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/doj-regrets-error-opm-linked-fraud-case/