Back to Blog
data breachesidentity theftprivacysocial security numbersdocument security

22 Million People Are About to Lose Their Breach Protection. Here Is What That Teaches the Rest of Us.

The identity protection given to victims of the 2015 OPM breach expires September 30, 2026. The real lesson is not about credit monitoring. It is about how long your Social Security number stays valuable to a stranger.

By RedactID Team7 min read
Conceptual vector illustration of a protective shield dissolving into particles while a padlock and redaction bars remain intact, in slate blue and navy

There is a deadline coming on September 30 that most people have not heard about, and it says something uncomfortable about how breach response actually works in practice.

Back in 2015, the U.S. Office of Personnel Management disclosed two cyberattacks. Together they affected roughly 22.1 million people. The first exposed personnel records for about 4.2 million current and former federal employees. The second, and far larger, exposed background investigation records for about 21.5 million people. Around 5.6 million sets of fingerprints were taken as well.

Background investigation files are not a list of names and email addresses. They are the most thorough dossier most people will ever have compiled about them: Social Security numbers, addresses going back years, employment history, financial details, health information, and details about relatives, roommates, and associates. Which is why a large share of the people affected had never applied for a federal job in their lives. They were simply listed on someone else's form.

Congress responded by requiring at least ten years of identity monitoring and protective services for those affected, with a statutory identity theft insurance floor of at least five million dollars.

Ten years is now up.

The clock ran out on the response, not the risk

Coverage has been ending on a rolling basis as individuals hit the ten year mark from their own enrollment date. Some people have already lost it. The program is scheduled to end entirely no later than September 30, 2026.

In early August, Senator Mark Warner of Virginia and Delegate Eleanor Holmes Norton of D.C. introduced legislation to make the coverage permanent, called the RECOVER PII Act. Warner put the reasoning plainly in the announcement: "The data stolen included workers' most sensitive and personal information, from Social Security numbers to security clearance records, and once that information is in the hands of a bad actor, you don't get it back."

Norton made the same point from the other direction: "Because there is no limit on how long personal information can be exploited, Congress must protect these federal employees and contractors in perpetuity."

Whether the bill passes is genuinely uncertain. Similar proposals have been introduced before and did not become law, and as of early August the sponsors and cosponsors were all Democrats in a Congress controlled by Republicans. We are not going to pretend to know how that lands.

But the argument underneath it is not a partisan one, and it is not really about federal employees. It is a statement about the nature of the data itself.

A stolen SSN does not expire

This is the part worth sitting with.

When your credit card number leaks, the bank cancels the card and mails you a new one. The stolen number becomes worthless within days. The system has a reset button.

Your Social Security number has no reset button. Neither does your date of birth, your mother's maiden name, your address history, or your fingerprints. A number stolen in 2015 works exactly as well in 2026 as it did the week it was taken. There is no expiry date on the data, which is exactly why an expiry date on the protection feels so strange.

There is a second-order problem too. Someone who was a junior analyst when those records were taken might hold a sensitive position now. The stolen file did not change, but its value to a foreign intelligence service grew as that person's career did. Data that seemed low-stakes at the time appreciates quietly in someone else's archive.

That is the real asymmetry of breaches. Your exposure is permanent. The institutional response to it is temporary and has a budget line.

What monitoring actually does, and what it does not

Credit monitoring is useful. It is not protection, and the naming has always been a little generous.

Monitoring is a smoke alarm. It tells you something is already burning so you can respond faster than you otherwise would. It does not make the house less flammable, and it certainly does not un-burn anything. When a company offers twelve or twenty four months of free credit monitoring after losing your records, what it is offering is a faster notification of consequences it already caused.

None of it retrieves the data. Once a file is copied, it is copied. Every breach response in existence is downstream cleanup.

So if the response side is fundamentally limited, the only lever with real leverage is the input side: how much sensitive data ends up in each place to begin with.

The lever you actually control

You cannot control whether your former employer, your insurer, or a government agency gets breached. That decision is not yours and never was.

You can control what is in the copy you hand over.

Think about how many documents you sent in the past year. A pay stub to a leasing office. A bank statement to a lender. A driver's license photo to a rental agent or a background check portal. Each one is now a permanent copy sitting in someone else's inbox, on someone else's server, protected by security practices you have never seen and cannot audit.

When one of those recipients gets breached in 2029, what leaks is whatever you sent in 2026. Not what they needed. What you sent.

That gap between what a recipient needs and what a document actually contains is usually enormous. A landlord verifying income needs your name, the pay period, your employer, and the amount. The stub itself also carries your full Social Security number, sometimes a bank account number, and deductions that reveal your health and retirement decisions. A lender confirming a balance needs the balance, not a full accounting of where you shop and who you pay.

Redacting before you send does not make you paranoid. It makes the eventual breach of that recipient less expensive for you. It is the only part of this whole chain where your decision actually changes the outcome.

That is what RedactID is for. You open a document in your browser, black out the fields nobody needs, and export a flattened file where the hidden text is genuinely gone rather than covered with a black rectangle you can drag away. Nothing uploads and nothing gets stored, because the processing happens on your device. If we held your files, we would just be one more inbox waiting to become a headline.

The practical read

If you were caught up in the OPM breaches, check any notice you get directly from MyIDCare rather than assuming you are covered through September. Credit freezes at Equifax, Experian, and TransUnion are free, have to be placed separately with each bureau, and do more to block new account fraud than monitoring does. The FTC has straightforward guidance on freezes and fraud alerts.

For everyone else, the lesson generalizes cleanly. Protection programs have end dates. Your data does not. Somewhere between those two facts sits every document you are about to email this month.

Send less. It is the only part of this you own.

Related reading: what to redact on a bank statement, how to share a pay stub safely, and redacting ID documents before sending them.

If you want to reduce what you hand over, RedactID is free to try daily, with credit packs and Pro for people who redact often.

Sources: CyberScoop, August 4, 2026 and MyFederalRetirement, August 5, 2026.

Ready to Protect Your Privacy?

RedactID lets you redact sensitive information from documents without uploading them — everything is processed on your device.