It took several weeks before the U.S. Office of Personnel Management (OPM) admitted that nearly 22 million personnel and security files had been leaked in two separate attacks. 
Months later, OPM and the Department of Defense (DoD) admitted that “Out of the 21.5 million individuals whose Social Security numbers and other sensitive information were leaked, there are also many individuals whose fingerprints stored on the federal agency's servers have been stolen.”
To be precise, out of a total of approximately 11 million files, 5.6 million have been stolen.
The OPM service's excuse for this delay was that the Ministry of Defense was conducting “analysis of the data that have been affected for verification of their quality and completeness.”
Government experts believe that, “the ability to abuse fingerprint data is limited.” Is that true?
OPM reports:
“This probability could change over time, as technology evolves, therefore, an interagency working group with experience in this field (such as the FBI, DHS, DOD, and other intelligence agencies) will review the possible ways attackers could use fingerprint data they have obtained now and in the future.”
It is known, however, that fake fingerprints are not used only in movies and television shows to bypass security. It is not just fantasy, it is reality. Since the release of the first iPhone with TouchID, fingerprint scanners have become a permanent part of our lives.
Replicating fake fingerprints is simple and can be used in everyday life. For example, Marc Rogers, a security researcher at Cloudflare, demonstrated how easy it was to hack Apple's TouchID on two iPhones (the 5S and the 6). With real fingerprints, like the ones the hackers stole, theft would be a breeze.
The OPM and US Department of Defense scandal reminds us that files stored for biometric security measures cannot be altered the way a password can be in the event of a leak after a hack.
