U.S. lawmakers have introduced the bipartisan RECOVER PII Act to provide lifetime identity-protection services to people affected by the 2015 Office of Personnel Management breaches, replacing benefits that are set to expire after the current 10-year coverage period. The proposal comes before existing protection for enrollees in the MyIDCare program begins ending on Sept. 30, and would preserve at least $5 million in identity-theft insurance for affected individuals.
The OPM intrusions exposed highly sensitive personnel and background-investigation records tied to about 22.1 million current, former, and prospective federal employees, contractors, and others. Supporters of the bill, including Sen. Mark Warner and Del. Eleanor Holmes Norton, say the stolen data still poses long-term personal and national security risks because foreign intelligence services can retain and correlate the records over time to identify or target government personnel and their families; the legislation would also let agencies reimburse workers for privacy tools and online information-removal services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In 2017, Congress responded to the OPM breach through an appropriations law requiring OPM to provide at least 10 years of complimentary identity-protection services to victims. The law also required no less than $5 million in identity-theft insurance for affected individuals.
The Office of Personnel Management breaches were disclosed in 2015 and compromised personnel records and background-investigation data affecting roughly 22.1 million current, former, and prospective federal employees, contractors, and others. One intrusion exposed about 4.2 million personnel records, while another compromised 21.5 million background-investigation records, with about 3.6 million people affected in both incidents.
Sen. Mark Warner and Del. Eleanor Holmes Norton are introducing the RECOVER PII Act, with Sens. Tim Kaine, Angela Alsobrooks, and Chris Van Hollen as Senate cosponsors. The bill would replace the current 10-year limit on identity-protection services for OPM breach victims with lifetime coverage, preserve identity-theft insurance, and allow agencies to reimburse workers for privacy tools and online information-removal services.
Some people enrolled in OPM's MyIDCare program began receiving notices late last year that their complimentary identity-protection coverage would end 10 years after their enrollment date. The notices are expected to continue through September as the program winds down.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcescworld.com
Open sourcemalware.news
Open sourcenextgov.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.