This isn't negligence. Instead of trying to protect data and networks the US government has made "cyber crime" a military issue. They've been doing it deliberately and publicly, for over a decade. Domestically they followed the same plan: companies get protection (financial, legal, image,) discouraging them from taking security seriously, and individuals get the CFAA which has a similar effect. They want data and network security to be a military problem, not to encourage security.
We can't blame the OPM for the security issues. They were a victim of a bad national strategy.
If you "see something, say something" unless its about cyber security.