U.S. Office of Personnel Management sued in data breach class action

Data SecurityA former U.S. attorney’s office employee filed a proposed class action in Kansas federal court accusing the federal Office of Personnel Management of allowing hackers to steal the personal information of millions of current, former and prospective federal employees by failing for years to address deficiencies in its security systems.

The plaintiff, Mary Woo, alleges in her complaint that the agency’s decentralized structure and refusal to address weaknesses identified through audits by its Office of Inspector General have resulted in numerous hacks, most notably two announced in quick succession this summer that compromised the personal information of at least 22.1 million people and led to Director Katherine Archuleta’s resignation.

The complaint also accused KeyPoint Government Solutions — the contractor tasked with handling most of the federal background checks managed by the OPM — of being incapable of protecting the data it collected and allowing OPM credentials to fall into the wrong hands.

Hackers are already taking advantage of the information they’ve stolen, mimicking OPM emails offering fraud protection in phishing attacks and reportedly selling OPM log-in credentials online, according to the complaint.

The case is Woo v. Office of Personnel Management et al, case number 6:15-cv-01220, in the U.S. District Court for the District of Kansas.

Steve Larson

An experienced trial lawyer who handles both hourly and contingent fee cases, Steve has expertise in class actions, environmental clean-up litigation, antitrust litigation, securities litigation, corporate disputes, intellectual property disputes, unfair competition claims, and disputes involving family wealth. Steve regularly represents individuals and businesses in federal and state court and has obtained class-wide recovery in multiple class actions. A veteran practitioner, Steve’s clients value his creative approach to resolving complex litigation matters.

Share: 

Legal Disclaimer

The information contained in this blog does not constitute legal advice, and does not create an attorney-client relationship. We make no claims, promises or guarantees about the accuracy, completeness, or adequacy of the information contained in or linked to this blog.