Pentagon Data Breach Exposes Sensitive Data of Over 3 Million People
Pentagon confirms a DMDC breach exposing SSNs and other data of about 3 million people.
The Pentagon confirmed unauthorized access to the Defense Manpower Data Center that exposed personal data tied to more than 3 million people, including 2.76 million living individuals and about 294,000 deceased people. A small number of unauthorized users reached unencrypted files through a file-sharing vulnerability from October 2025 until DMDC found and patched it on July 16, 2026. Exposed data can include names, Social Security numbers, dates of birth, contact details, and military occupational information. Officials say they have no evidence of misuse; notification letters dated September 18 offer one year of IDX credit monitoring.
- Unauthorized access lasted from October 2025 until discovery on July 16, 2026.
- About 2.76 million living people and 294,000 deceased individuals were exposed.
- Unencrypted files included names, SSNs, birth dates, and military job details.
- Officials report no evidence the stolen data has been misused so far.
- Affected people are offered one year of IDX credit monitoring.
Full article552 words · extracted from gbhackers.com · click to collapse
The Pentagon has confirmed a major data breach involving the Defense Manpower Data Center (DMDC) information system, exposing sensitive personal information linked to more than three million individuals.
The breach affects 2.76 million living people and approximately 294,000 deceased individuals. The scale of this exposure has intensified scrutiny on the DMDC, one of the Department of Defense’s most critical personnel data repositories.
According to CSN, a small number of unauthorized users accessed personally identifiable information stored within the DMDC from October 2025 to July 2026.
The intrusion stemmed from a vulnerability in a file-sharing system that allowed access to files on an affected server. DMDC discovered the weakness on July 16, patched the vulnerable system, restored operations, and initiated privacy and cybersecurity incident-response procedures.
Pentagon Data Breach
The accessed files reportedly contained unencrypted personally identifiable information. Depending on the individual, the exposed data may include names, Social Security numbers, dates of birth, contact information, gender, race, and military personnel details, including occupational specialties.
Exposing Social Security numbers alongside biographical and employment data creates a significant long-term risk of identity theft. Threat actors can combine these data points with public records, previous breach data, social media profiles, or commercial databases to commit identity theft, open fraudulent accounts, and execute highly tailored phishing and impersonation scams.
Military occupational information also raises potential counterintelligence concerns. Job specialty details might help adversaries identify individuals associated with sensitive roles, map personnel functions, or develop credible pretexts for spear-phishing and social-engineering operations.
The DMDC serves as a central repository for identity and personnel data across the defense community. Its systems maintain records for active-duty and reserve service members, civilian employees, contractors, retirees, veterans, military family members, and other affiliated individuals.
Although DMDC reportedly manages over 60 million personnel records in total, officials have not stated if all records were involved in this incident.
The breach’s most alarming concern is its duration. Unauthorized access may have continued from October 2025 until the vulnerability was identified in July 2026, leaving the exposed files vulnerable for approximately nine months. Officials have not publicly identified the intruders, disclosed their motives, or explained why the sensitive files were stored without encryption.
Defense officials indicated that they currently have no evidence that the compromised information has been misused. However, this does not eliminate future risks, as Social Security numbers and dates of birth cannot be easily changed once exposed.
Impacted individuals are being offered one year of free credit monitoring and identity restoration services through IDX. Notification letters dated September 18 began reaching affected personnel.
Recipients should enroll in the protection service promptly, review their credit reports, monitor financial and government benefit accounts, and treat unexpected messages referencing military employment with caution.
This incident underscores the need for the Pentagon to encrypt stored data, enforce strict access controls, continuously monitor file access, detect anomalies quickly, and adopt data minimization practices.
Investigators continue working on determine who accessed the files, what specific data was collected, and whether the breach was driven by fraud, espionage, or another form of unauthorized activity.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.