Identity Protection
Your Free OPM Breach ID Protection Is Ending Sept 30 — Here's What to Do Next
Bottom line: If you were a federal employee, retiree, contractor, or someone who went through a federal background check around 2015, you may have been one of the 22.1 million people affected by the OPM data breaches — and the free identity theft protection you were given because of it is shutting down. Coverage ends on a rolling basis as each person hits 10 years of enrollment, and the entire program closes for good no later than September 30, 2026. A bill to extend it to lifetime coverage was just introduced in Congress this month, but it has not passed, and you should not count on it. You have about five weeks to check your enrollment date, freeze your credit with all three bureaus, and decide whether to replace the free coverage with something paid.
What's Actually Ending, and Why September 30 Matters
Back in 2015, the U.S. Office of Personnel Management (OPM) — the agency that handles records for federal employees — was hit by two massive data breaches. Hackers stole detailed personal records, including Social Security numbers, fingerprints, and in many cases the sensitive information collected during federal background investigations.
Because the breach was so severe, Congress required OPM to provide free identity theft monitoring and identity theft insurance to everyone affected. That protection has been delivered through a program called MyIDCare, funded under the 2017 Consolidated Appropriations Act, and it was designed to run for 10 years.
Those 10 years are now up. Coverage isn't ending all at once for everyone on the same day — it ends individually, 10 years from the date each person originally enrolled. But the government funding behind the entire program runs out no later than September 30, 2026, which is the hard outer deadline even for people who enrolled a bit later than others.
If you've received a notice in the mail or by email from MyIDCare in the past several months, this is what it's about. If you haven't received one yet but believe you were affected, don't assume you're in the clear — notices have been going out on a rolling basis since late 2025, and not everyone gets one at the same time. If you're not sure whether the 2015 OPM breach is the only exposure you should be worried about, it's worth learning how to find out if your information was in any data breach, not just this one.
Are You One of the 22.1 Million? You Might Not Realize It
This is the part people miss most often: you didn't have to work for the federal government to be affected.
The two 2015 breaches covered different groups:
- About 4.2 million people — current and former federal employees whose personnel records were stolen.
- About 21.5 million people — everyone swept up in the second, larger breach of federal background investigation records.
That second group is much broader than "federal employees." Background investigations collect information not just on the applicant, but often on their spouses, close family members, and personal references. If a family member ever applied for a federal job, a security clearance, or certain federal contracts and you were listed as a reference or a cohabitant, your information may have been included even if you never worked for the government a day in your life.
Combined, these two breaches affected roughly 22.1 million people — one of the largest breaches of government records in U.S. history. If you're not sure whether you were included, look for a notice from MyIDCare, or check with the agency or family member connected to the original background check.
Your Real Deadline Might Be Sooner Than September 30
Here's the detail that catches people off guard: September 30, 2026 is the latest possible date, not necessarily your date.
Because coverage runs 10 years from each person's individual enrollment date, and enrollment happened over a period of months back in 2016, some people's coverage has already ended or will end well before the September deadline. Others land right at the wire.
The only way to know your actual date is to look at the notice MyIDCare sent you. If you can't find it or aren't sure you received one, that's worth chasing down now rather than in September — don't wait for a second reminder that may not come.
What MyIDCare Actually Covered
It's worth understanding what you're losing, so you know what to replace and what you can skip.
MyIDCare has provided, at no cost to enrollees:
- Credit monitoring across the major credit bureaus, with alerts when new accounts or inquiries show up under your name.
- Identity monitoring, watching for your personal information showing up in places it shouldn't, like the dark web.
- Identity theft insurance, which helps cover certain out-of-pocket costs if your identity is stolen and you need to recover from it — things like lost wages or legal fees tied to fixing the fraud.
- Recovery assistance, meaning help from a case manager if your identity actually gets stolen, rather than leaving you to sort it out entirely on your own.
Once your coverage ends, all of that stops. You're not automatically left unprotected in the sense that your information suddenly becomes exposed — the original breach happened over a decade ago — but you lose the safety net that's been quietly watching for misuse of that stolen data ever since.
Is There Any Chance This Gets Extended?
Maybe, but don't plan around it.
This month, Senator Mark Warner (D-VA) and Congresswoman Eleanor Holmes Norton (D-DC) introduced companion bills in the Senate and House — known as the RECOVER PII Act — that would replace the current 10-year limit with lifetime identity theft protection for everyone affected by the OPM breaches. The bill would also help cover the cost of privacy tools used to scrub personal information from data broker sites.
It's a serious proposal from lawmakers who have pushed similar bills before. But that's part of the problem: similar extensions have been proposed in past years and did not become law. There's no guarantee this one passes before September 30, and even if it eventually does, a bill introduced in August moving through Congress in five weeks would be unusually fast.
The safe assumption is that your free coverage ends on schedule. If Congress extends it later, that's a pleasant surprise — not something to bank on.
What to Do Before Your Coverage Ends
You have a few weeks to get ahead of this. Here's the order that makes sense:
1. Find your MyIDCare notice and confirm your exact expiration date. This tells you how much runway you actually have — it may be less than five weeks.
2. Freeze your credit with all three bureaus — Equifax, Experian, and TransUnion — separately. This is free, permanent until you lift it, and is the single most effective step you can take on your own. A freeze blocks new credit accounts from being opened in your name, which is exactly the kind of fraud stolen background-check data enables. You can freeze your credit directly through each bureau's website; you do not need to pay a service to do this for you. If you want the exact steps for each bureau, see our full guide to freezing your credit for free.
3. Pull your free credit reports at AnnualCreditReport.com and check for anything unfamiliar — accounts you didn't open, inquiries you don't recognize.
4. Decide whether you want ongoing monitoring after MyIDCare stops, since a credit freeze protects against new-account fraud but doesn't watch for other forms of identity misuse, like your Social Security number being used for tax fraud or medical identity theft.
Why a Credit Freeze Alone Isn't the Whole Picture
A credit freeze is essential, but it has a blind spot: it protects your credit file, not everything a stolen Social Security number can be used for. It won't catch someone filing a fraudulent tax return in your name, using your identity for medical care, or opening accounts with companies that don't check the major credit bureaus at all.
That's the gap MyIDCare's monitoring and recovery assistance was quietly filling for the last decade. Once it's gone, you're on your own to notice a problem — unless you replace it with something that keeps watching. Knowing the warning signs that someone is already using your identity is worth reviewing now, before you lose the monitoring that would normally catch it for you.
Aura is built to cover exactly that gap. It monitors your Social Security number, credit reports across all three bureaus, bank and investment account activity, and the dark web for signs your information is being misused, and it includes identity theft insurance similar in spirit to what MyIDCare provided — up to $5 million in coverage depending on the plan, plus a U.S.-based case manager to help you recover if something does go wrong. For anyone who's relied on MyIDCare for a decade and doesn't want a gap in coverage after September 30, it's a reasonable like-for-like replacement. If you'd rather compare options before committing, see our roundup of the best identity theft protection for seniors, or if you specifically want ongoing credit monitoring rather than full identity protection, these credit monitoring services are worth a look too.
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
A Simple Timeline to Follow Before September 30
- This week: Locate your MyIDCare notice (check mail, email, and spam folders) and confirm your personal expiration date.
- This week: Freeze your credit with Equifax, Experian, and TransUnion if you haven't already.
- Within two weeks: Pull your three free credit reports and review them line by line.
- Before your coverage ends: Decide on a replacement monitoring service if you want to keep that protection going, and get it set up before the free coverage actually stops — not after.
- Ongoing: Keep an eye on news about the RECOVER PII Act, but don't delay your own preparations waiting on it.
None of these steps require paying anyone to "confirm your eligibility" or "verify your enrollment" over the phone. If you get an unexpected call or text about your OPM breach coverage asking you to confirm personal details, treat it as a likely scam — MyIDCare communicates through official mail and its own website, not unsolicited calls asking you to "verify" your Social Security number.
Common Questions About the OPM Coverage Ending
Do I need to do anything to keep my current MyIDCare coverage active until my expiration date?
No. Your existing coverage stays active on its own until your personal 10-year mark or September 30, 2026, whichever comes first. You don't need to renew or re-enroll to keep the coverage you already have running through that date — you only need to act to replace it once it ends.
What if I was affected but never actually enrolled in MyIDCare back in 2016?
You can still check your status. Being eligible and being enrolled aren't automatically the same thing, and some people who qualified never signed up. If you're not sure, that's worth resolving before assuming any coverage — active or otherwise — applies to you.
I never got a notice. Does that mean I wasn't affected?
Not necessarily. Notices have gone out on a rolling basis since late 2025, tied to each person's individual enrollment anniversary, so people whose 10-year mark falls later in the year may not have received theirs yet. If you know you were part of either 2015 breach and haven't heard anything, don't wait for a letter that might arrive closer to September — go looking for your enrollment status instead.
Is a credit freeze really free, or is that the catch?
It's genuinely free. Federal law requires all three credit bureaus to let you freeze and unfreeze your credit at no cost, as many times as you want. Be wary of any service that charges a fee specifically to "freeze your credit" — that's not a real cost you should have to pay.
Will I lose my identity theft insurance the moment my coverage ends, or is there a grace period?
There's no grace period built into the program. Once your individual 10-year window closes — or the program-wide funding ends on September 30, 2026, whichever hits first — the monitoring and insurance stop. That's exactly why it's worth having a decision made, not just considered, before that date arrives.
The Bottom Line
Ten years of free protection tied to one of the largest government data breaches in U.S. history is ending, on a rolling basis, no later than September 30, 2026. If you were a federal employee, retiree, contractor, or simply listed in someone else's background investigation back in 2015, this affects you whether or not you've noticed a notice yet. Find your date, freeze your credit now while it's still fresh in your mind, and make a deliberate decision about what — if anything — replaces the monitoring you're about to lose.
Stay One Step Ahead of Scammers
Every week, ClearShield sends a free email covering the newest scams targeting adults 55 and older. No spam. No sales pitches. Just plain-English alerts and the steps to protect yourself.
Thousands of readers count on ClearShield to keep them informed. Join them for free.
Last updated: 2026-08-25
Related reading
Best Identity Theft Protection for Seniors in 2026 — 6 Services Compared
We compared 6 identity theft protection services on monitoring depth, restoration support, and price. Here's which one actually earns its monthly fee.
How to Freeze Your Credit for Free: The Step-by-Step Guide Every Senior Needs
Freezing your credit is the single most powerful thing you can do to block identity theft. Here's exactly how to do it — free, at all three bureaus.
How to Freeze Your Credit for Free — A Step-by-Step Guide for Seniors
A credit freeze is free, takes 15 minutes, and is the single best thing you can do to stop identity thieves from opening accounts in your name.