Unconscionable. I would even say callous and criminal negligence, all on the current administration's watch, of the highly confidential and very private information of the people working for that same government.
An article by Mathew Schwartz on the databreachtoday site lays it out. He points at a litany of errors, which resulted in the current OPM Director Katherine Archeluta's resignation. The problems started years before she even came on board at OPM though, this is an inherited problem of long duration. Just have a look at this quote:
"Since 2007, the OPM Inspector General has continuously pointed out serious deficiencies in OPM's cybersecurity posture. OPM's response has been glacial," says Rep. Jim Langevin, D-R.I., a senior member of the House Committee on Homeland Security. The OPM's Office of the Inspector General issued a report in 2012, highlighting numerous weaknesses. Most damning, however, was OIG noting that it had been warning about "a material weakness in controls over the development and maintenance of OPM's IT security policies" since 2007.
"It repeated that warning in 2008, and added in 2009 that things were getting worse - affecting the organization's entire information security governance and management structure - after which it repeated the same warnings in 2010 and 2011. And in 2012, the OIG warned that the OPM's CIO office "continued to operate with a decentralized IT security structure that did not have the authority or resources available to adequately implement the new policies."
I really hope that whomever inherits the White House will take decisive action to prevent this in the future, and get serious on their defense-in-depth. Here is the article:
http://www.databreachtoday.com/blogs/opm-victim-as-a-service-provider-p-1883