Pentagon breach exposes Social Security numbers and military records of millions
Pentagon breach exposes Social Security numbers and military records of millions
The US government is alerting millions of people that their personal information was stolen during a breach of the Pentagon’s personnel records at the Defense Manpower Data Center (DMDC). The DMDC is a central US Department of Defense (DoD) organization that manages personnel records, ID credentials, and benefit entitlements for military and civilian staff, veterans, and their families. It…
Full article523 words · extracted from malwarebytes.com · click to collapse
The US government is alerting millions of people that their personal information was stolen during a breach of the Pentagon’s personnel records at the Defense Manpower Data Center (DMDC).
The DMDC is a central US Department of Defense (DoD) organization that manages personnel records, ID credentials, and benefit entitlements for military and civilian staff, veterans, and their families. It maintains over 60 million records for US military and civilian staff and their family members to help determine benefits and entitlements, such as healthcare and retirement.
Reportedly, cybercriminals had access from October 2025 to July 2026. CNN reports that the Pentagon confirmed the breach affects 2.76 million living individuals, potentially including current and former defense personnel or their dependents, and 294,000 deceased individuals.
A notification shared on Reddit states:
“A small number of unauthorized users accessed files on a server containing unencrypted PII.”
PII means personally identifiable information. The attackers gained access by exploiting a security vulnerability in an unspecified file-sharing system. The Pentagon says it has “no indication” of misuse. It hasn’t explained how it reached that conclusion or what it considers misuse, and it doesn’t rule out future misuse of the exposed information.
The exposed data is said to include Social Security numbers, names, dates of birth, sex, race, and service details. Some records also include contact information and occupational specialty.
Besides the risk that this data could help foreign intelligence services track US personnel, affected people face a lasting risk of identity theft. Birth dates cannot be changed, and Social Security numbers can only be changed in limited circumstances.
Breaches happen every day. Don’t be the last to know.
What to do if you’re affected
The Pentagon is offering 12 months of credit monitoring through IDX. If you receive a notification letter, take up the offer and consider a credit freeze with all three major credit bureaus: Equifax, Experian, and TransUnion. A freeze is free and restricts access to your credit report, helping prevent someone from opening new credit accounts in your name.
Other recommendations are:
- Get an IRS Identity Protection PIN to prevent someone else from filing a federal tax return using your Social Security number.
- Be suspicious of unexpected calls, emails, and texts, especially ones that mention your unit, rank, or job. Attackers can use the stolen details to make phishing attempts more convincing.
- Verify requests through official channels you look up yourself, rather than through contact details in the message.
- Use unique passwords and multi-factor authentication on email, banking, and benefits accounts.
- Limit location sharing and review privacy settings on phones and apps, since military leaders have raised concerns about commercial location data being used to target personnel.
- Follow instructions in the breach letter and further official communications and report any suspicious approach to your security officer.
Let’s face it, an incognito window can only do so much. Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
About the author
Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.