On 4 June 2015 the United States Office of Personnel Management announced that the records of about four million federal employees had been taken; the count for that system was later settled at 4.2 million. Nothing about the intrusion was recent. Investigators dated the decisive access to 7 May 2014, when attackers posing as staff of a background-investigation contractor, KeyPoint Government Solutions, entered the network on valid credentials; the command-and-control domains they ran it from had been registered under the names Steve Rogers and Tony Stark. A separate exfiltration had been reported to the Department of Homeland Security by an outside party on 20 March 2014. The 2014 breach was not found until 15 April 2015, and who found it — a vendor demonstrating forensic software, or the agency's own staff running Cylance — was argued over for a year.

Eight days later the agency confirmed the worse half. On 12 June officials acknowledged that a second system had also been reached: the one holding background-investigation files. That system stored the Standard Form 86, the Questionnaire for National Security Positions — 127 pages on which an applicant sets down relatives and their addresses, former college roommates, every foreign national known well, foreign travel, arrests, debts, drug use and treatment for mental health, then supplies references who are themselves interviewed. The FBI director, James Comey, called the collection a treasure trove covering everyone who had worked for the United States government, or tried to. A personnel file can be replaced. A completed SF-86 is a map of a person's obligations, and it does not expire.

The hearings began on 16 June, when the director, Katherine Archuleta, appeared before the House Oversight Committee. Its chairman, Jason Chaffetz, pressed her on unencrypted systems and on recommendations to take vulnerable ones offline that had not been followed; encryption, officials countered, would have made no difference to intruders holding valid credentials. A Democrat on the committee, Stephen Lynch, said he knew less coming out of the hearing than going in. The warnings were on the record. The agency's inspector general reported in November 2014 that OPM held no complete inventory of its own servers and required no multi-factor authentication for remote access, and counted the eleven major systems then running without a valid authorisation as a material weakness; on 17 June, the day after the hearing, it issued a flash audit alert warning that the emergency overhaul of the agency's infrastructure had no settled scope, cost or business case. Two of its background-check contractors, USIS and KeyPoint, had themselves been breached during 2014.

What June did not yet know arrived in July. On 9 July 2015 the agency put the background-investigation total at 21.5 million people — applicants, spouses, cohabitants — including 1.1 million sets of fingerprints, a figure revised that September to 5.6 million; across both intrusions, 22.1 million records. On 10 July, a day after saying she would not go, Archuleta resigned. Officials attributed the theft to China in background briefings and never formally; Beijing denied it. Nobody was ever charged with the intrusion itself. The nearest thing was Yu Pingan, a Chinese national arrested at Los Angeles airport on 24 August 2017 over Sakula, the malware family used at OPM — though the charges against him named four other American companies, not the agency; he pleaded guilty, was sentenced in February 2019 to the roughly eighteen months he had already served, and was deported. The director of national intelligence, James Clapper, said publicly that one had to salute the Chinese.

Also that month · 10 June

A nation-state in the laboratory

On 10 June 2015 Kaspersky Lab published a report on an intrusion into its own network. The company had found it while testing a prototype of its own platform for detecting advanced attacks — the product caught the intruder in the building that made it. The malware was a new generation of Duqu, the tool found in 2011 and related to Stuxnet; the researchers called it Duqu 2.0. It lived almost entirely in memory, wrote nothing lasting to disk, reinfected cleaned machines from a foothold elsewhere on the network, and used a Windows kernel flaw, CVE-2015-2360, patched that same month. Kaspersky said the same platform had been found on computers at venues used for the P5+1 negotiations over Iran's nuclear programme, and at an event marking the seventieth anniversary of the liberation of Auschwitz-Birkenau. Researchers and later press reports linked the group to Israel, which denied it; no government confirmed anything. The unusual part was the telling — a security company announcing that a state had been inside it, and saying so before anyone else could.

Also that month · 15–21 June

A vault, a database and a flight plan

On 15 June LastPass posted a notice signed by its chief executive, Joe Siegrist: email addresses, password reminders, per-user salts and authentication hashes had been taken. Encrypted vaults, the company said, had not. Master-password changes were urged; the reminders, one cryptographer observed, were useful in themselves to an attacker who already had the address. On 16 June the New York Times reported that the FBI was investigating employees of the St Louis Cardinals for entering Ground Control, the Houston Astros' private database of scouting reports, medical notes and trade talks. The route in, prosecutors said, was a password an executive had handed over with his laptop when he left St Louis for Houston after the 2011 season; that executive, Jeff Luhnow, by then the Astros' general manager, called the suggestion he had reused his old passwords "absolutely false" on 18 June. Chris Correa, the Cardinals' scouting director, pleaded guilty and was sentenced to 46 months and $279,038.65 in restitution; in January 2017 baseball banned him for life and moved two of his club's draft picks and $2 million to Houston. On 21 June a denial-of-service attack on LOT Polish Airlines' flight-plan computers at Warsaw Chopin left the airline unable to issue plans for about five hours: ten flights cancelled, a dozen delayed, 1,400 passengers on the ground.

India desk · June 2015

A day to fix, and nobody told

In the same fortnight that Washington admitted losing four million personnel files, a security researcher, Anand Prakash, told Zomato that one of the restaurant app's interfaces would return another user's record if a numeric parameter was changed. Any of the app's 62.5 million registered users could be read that way — name, email address, phone number, date of birth, home address — and, for accounts linked to Instagram, an access token that opened private photographs. He reported it on 1 June; by his own timeline Zomato acknowledged and closed the hole the following afternoon, and he published the details on 9 June. No announcement was made and no user was written to, because none had to be: Indian law in 2015 imposed no duty to notify. Two weeks earlier a hacker in Lahore had put up a searchable copy of the music service Gaana's users and claimed the database held more than ten million (May 2015). India's first national cyber security coordinator, Gulshan Rai, had been in post since 1 April, moved from CERT-In into the Prime Minister's Office.

The country was moving the other way that month. On 25 June the Smart Cities Mission was launched, and on 1 July the prime minister launched Digital India — identity, services and records online at national scale — in the same weeks the American month showed what a government loses when it loses fingerprints. India was already building the world's largest biometric database: ten fingerprints and two iris scans a person. On 11 August 2015 the Supreme Court ordered the government to publicise that Aadhaar was not mandatory for welfare; privacy became a fundamental right on 24 August 2017, and the Aadhaar judgment followed on 26 September 2018. CERT-In later told Parliament that 49,455 incidents were recorded in India during 2015, and 394,499 in 2019. The distance between a quiet fix and a required announcement is what CERT-In's six-hour direction of 2022 and the DPDP Act of 2023 closed.

AI Tech desk · June 2015

The label Google never put back

On 29 June 2015 a programmer in Brooklyn, Jacky Alciné, posted screenshots of Google Photos, released a month earlier, filing pictures of him and a friend, both Black, under "gorillas". Yonatan Zunger, Google's chief architect of social, answered within hours that it was not acceptable; the company said it was appalled and genuinely sorry. The repair went to the vocabulary, not the classifier: the tag was withdrawn rather than corrected, and when the New York Times tested in May 2023 neither Google's app nor Apple's could find a gorilla at all. It is where every later argument about algorithmic bias begins. The month also had the technology admired. Google's research blog posted Inceptionism on 17 June, the pictures a network makes when told to amplify what it sees, the DeepDream code following on 1 July; ImageNet's organisers barred a Baidu team on 2 June for twelve months over at least two hundred test-server submissions from at least thirty accounts; and on 23 June Amazon's Echo went on general sale at $179.99, Alexa opened to outside developers two days later.

Digital Guard desk · June 2015

A billion-pound listing and a wormable scanner

On 26 June 2015 Sophos began conditional dealings on the London Stock Exchange at 225 pence a share, valuing the Oxfordshire company at £1,013 million, raising about $125 million for the business and £272.6 million for the shareholders selling into it; a third of the equity went to the market, and unconditional admission to the premium segment followed on 1 July. One analyst doubted the premium would hold. The company left the exchange in March 2020, taken private by Thoma Bravo. Three days before the float Google's Project Zero published Tavis Ormandy's teardown of ESET's NOD32 emulator: a remote, self-propagating route to root or SYSTEM on every supported edition in its default configuration. ESET, notified on 19 June, shipped a fix in ordinary signature updates on the 22nd, and said the flaw lay in one scanner's emulation routine rather than the core engine and had already gone from its pre-release code — a point Kaspersky's disclosure of its own intrusion had made a fortnight earlier. Project Zero went on to do the same to Kaspersky, FireEye and Symantec.

⏳ Time capsule — June 2015

  • On 2 June Sepp Blatter announced that he would resign as president of FIFA, amid the corruption investigations then engulfing the organisation.
  • On 6 June American Pharoah won the Belmont Stakes to take the Triple Crown, the first horse in thirty-seven years to do so.
  • On 21 June the first International Day of Yoga was observed; 35,985 people, including the prime minister and dignitaries from 84 nations, held 21 postures for 35 minutes on Rajpath in New Delhi, the largest yoga class recorded.
  • On 26 June the United States Supreme Court decided Obergefell v. Hodges by five votes to four, Justice Anthony Kennedy writing, holding that the Fourteenth Amendment requires states to license and recognise same-sex marriages.
Where it stands today — 2026

A file that does not expire

A decade on, June 2015 changed what a breach costs. The remedy offered at the time was credit monitoring — eighteen months of it — for a loss that had almost nothing to do with credit. Fingerprints cannot be reissued, and a background-investigation file cannot be un-read; the counter-intelligence argument about how many careers it ended has run ever since. The legal ending was smaller. A $63 million settlement was approved in 2022; when the case closed in December 2024, about $4.8 million had reached just over five thousand people, and $58.2 million returned to the Treasury. No state was ever charged. The archive's later China-attributed intrusions — the Microsoft signing key of July 2023 and the wiretap systems of October 2024 — are the same argument, continued.

The other three aged differently. Kaspersky's decision to publish its own compromise set a standard vendors are still measured against, even as the company's later troubles turned on the same deep access. LastPass's loss of hints in 2015 reads as minor beside 2022, when encrypted vaults were taken and the company agreed in 2025 to settle the consumer class action for $24.45 million. LOT's five hours in Warsaw showed that an airline can be stopped by a network rather than by weather — and, as the airline's own spokesman pointed out at the time, the ground system that failed was one carriers everywhere were running. The Cardinals case stayed the month's cleanest lesson: no state, no malware, just a password that travelled with a laptop from one employer to the next. And in India, the gap June exposed between fixing a hole and admitting one closed by rule in 2022 and by statute in 2023.