From the report: On March 20, 2014, US-CERT notified OPM that a third party had reported data exfiltration from the OPM's network.
I think it's likely it was NSA that made the notification. Maybe not. Either way, what further could NSA have done about it? The NSA can't make another federal agency improve its computer security. At best it can perform audits: which it appears to have done; OPM had the lowest security posture of any agency.
Should the NSA have prevented the exfiltration? How would that work? Do you want the NSA to have the authority to cut network connections occurring in the U.S. internet? Should the NSA have authority over civilian government agencies? What about hacking and wiping the intruders' endpoints? Sounds like an act of war to me, if those endpoints are on Chinese soil.
I doubt the vast majority of HN'ers want an increase in NSA's authority or scope.