Pentagon breach exposes personal data of more than 3 million people
Pentagon DMDC says a file-sharing flaw exposed unencrypted personal data, including SSNs, of about 3 million people.
The Pentagon’s Defense Manpower Data Center is notifying about 3.05 million people—2.76 million living and 294,000 deceased—that unauthorized users accessed unencrypted personal files. A file-sharing vulnerability, found on July 16, 2026, had allowed access since October 2025. Exposed data varied by person and included Social Security numbers, names, birth dates, contact details, demographics, and military job specialties. DMDC says it has no indication of misuse and is offering 12 months of free IDX credit monitoring.
- About 2.76 million living people and 294,000 deceased individuals are affected.
- Unauthorized access ran from October 2025 until discovery on July 16, 2026.
- Files held unencrypted SSNs and other personnel identifiers.
- DMDC reports no known misuse and offers 12 months of credit monitoring.
Full article256 words · extracted from helpnetsecurity.com · click to collapse
The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of people that hackers gained access to their personal data.

The breach affects 2.76 million living individuals, a group that can include current and former defense personnel and their dependents, along with 294,000 deceased individuals, a Defense Department official told CNN.
Established in 1974, DMDC serves as a central hub for US Department of Defense data on military personnel, service status and benefits eligibility.
According to data breach notification letters shared online by affected individuals, DMDC discovered “a security vulnerability in a DMDC file sharing system” on July 16, 2026, which “allowed unauthorized users to access files.”
“Analysis identified that between October 2025 and the date of discovery, a small number of unauthorized users accessed files on a server containing unencrypted PII,” the letters say.
The exposed data differed from person to person and included Social Security numbers paired with names, birth dates, contact information, race, sex and military job specialties.
DMDC says it “does not have any indications of misuse of the accessed information,” and has not disclosed who accessed the files or whether they were copied.
“We are taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system,” the letters note.
DMDC is offering affected individuals 12 months of free credit monitoring through IDX, a breach response company contracted by the department.
This breach is the second blow to US federal agencies in a matter of weeks, after the ShinyHunters extortion group claimed it stole personal information of FBI employees.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/10/01/pentagon-dmdc-data-breach-3-million-people/