First OPM admitted that some four million personnel files were in foreign hands, but then it came our that number number was probably more like 14 million.
Now would you believe… 18 million? And would you believe OPM is still sticking by its original admission?
Of course you would:
FBI Director James Comey gave the 18 million estimate in a closed-door briefing to Senators in recent weeks, using the OPM’s own internal data, according to U.S. officials briefed on the matter. Those affected could include people who applied for government jobs, but never actually ended up working for the government.
The same hackers who accessed OPM’s data are believed to have last year breached an OPM contractor, KeyPoint Government Solutions, U.S. officials said. When the OPM breach was discovered in April, investigators found that KeyPoint security credentials were used to breach the OPM system.
Some investigators believe that after that intrusion last year, OPM officials should have blocked all access from KeyPoint, and that doing so could have prevented more serious damage. But a person briefed on the investigation says OPM officials don’t believe such a move would have made a difference. That’s because the OPM breach is believed to have pre-dated the KeyPoint breach. Hackers are also believed to have built their own backdoor access to the OPM system, armed with high-level system administrator access to the system. One official called it the “keys to the kingdom.” KeyPoint did not respond to CNN’s request for comment.
From there, things get worse:
OPM’s internal auditors told a House Oversight and Government Affairs Committee last week that key databases housing sensitive national security data, including applications for background checks, had not met federal security standards.
“Not only was a large volume (11 out of 47 systems) of OPM’s IT systems operating without a valid Authorization, but several of these systems are among the most critical and sensitive applications owned by the agency,” Michael Esser, OPM’s assistant inspector general for audits, wrote in testimony prepared for committee.
I was going to say Washington needs a reboot, but what it really needs is its hard drives scrubbed and a clean reinstall.
EXIT QUESTION: Will Team Hillary at some point attempt to spin her private email server as a security precaution against Chinese hackers?