Pentagon DMDC breach exposed data on about 3.05 million people
Unauthorized access to unencrypted DMDC files exposed Social Security numbers and other personnel data for 2.76 million living and 294,000 deceased people.
The Pentagon’s Defense Manpower Data Center is notifying people that unauthorized users reached unencrypted files on a file-sharing system from October 2025 until July 16, 2026, when the vulnerability was discovered and patched. Several outlets put the impact at 2.76 million living people and 294,000 deceased individuals, about 3.05 million, while TechCrunch cited rounded figures of about 2.8 million living and nearly 300,000 deceased and a total near 3.1 million; SecurityWeek attributed the precise counts to a Department of War official, and other reports cited the Pentagon or Defense Department. Exposed information varied by person and can include names, Social Security numbers, dates of birth, contact details, sex, race or other demographics, and military occupational or service data. Officials say the intruders are unidentified, no group has claimed responsibility, and there is no indication of misuse, although some outlets describe the records as stolen rather than merely accessed. People affected are offered 12 months of IDX credit monitoring, with GBHackers reporting September 18 notification letters and Security Affairs an August 19, 2027 enrollment deadline; no report named a CVE, and an early account raised counterintelligence concerns without a count.
- Unauthorized users reached unencrypted files on a Defense Manpower Data Center file-sharing system from October 2025 until a vulnerability was found and patched on July 16, 2026.
- The most specific counts are 2.76 million living people and 294,000 deceased individuals, about 3.05 million; TechCrunch cited rounded figures of about 2.8 million living and nearly 300,000 deceased, and about 3.1 million overall.
- Exposed data varied by person and can include names, Social Security numbers, dates of birth, contact details, sex, race or other demographics, and military occupational or service information.
- Officials say intruders are unidentified, no group has claimed responsibility, and there is no indication of misuse; outlets disagree on whether records were stolen or only accessed.
- Affected people are offered 12 months of IDX credit monitoring; GBHackers reported notification letters dated September 18, and Security Affairs an enrollment deadline of August 19, 2027.
- No report named a CVE. Security Affairs said DMDC held at least 60 million records in fiscal 2024.
- Malwarebytes described DMDC as managing personnel records, ID credentials, and benefits for military and civilian staff, veterans, and families.
Coverage timelineoldest first · each row is one article
- · 5d agoPentagon data breach of military personnel raises national security concerns
DataBreaches.net· 80
Unauthorized access to a Pentagon HR server exposed Social Security numbers of current and former military personnel.
- · 2d agoPentagon Data Breach – Hackers Reportedly Accessed 3 Million People’s Sensitive Data
Cyber Security News· 84
Pentagon confirmed a DMDC breach exposing unencrypted personal data, including Social Security numbers, of roughly three million people.
- · 2d ago