Hackers stole Pentagon personnel records of over 3 million people

Breach of Defense Manpower Data Center exposed sensitive data for nearly a year; free credit monitoring offered

edit
By LineZotpaper
Published
Read Time2 min
The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the human resources management system in October 2025, exploiting a vulnerability in file-sharing systems that went undetected until July 2026.

The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025.

In data breach notification letters shared online by affected individuals, the DMDC told affected military personnel that "a small number of unauthorized users" had access to their sensitive data, including personally identifiable information (PII), between October 2025 and July 2026 after exploiting a vulnerability in its file-sharing systems.

The stolen data varies by person and includes Social Security numbers (SSNs), names, dates of birth, contact information, sex, race, and military personnel information.

Pentagon officials told Federal News Network that the data breach affects more than 3 million people, including nearly 2.8 million living individuals and 294,000 "deceased individuals."

"Upon discovery of the security vulnerability, DMDC immediately initiated privacy and cybersecurity incident response actions in accordance with Office of Management and Budget and Department guidelines and policies," the DMDC told affected individuals. "We are taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system."

The Pentagon is also offering 12 months of free credit monitoring services through the IDX data breach and recovery service provider and says affected individuals must enroll by August 19, 2027.

Founded in 1974, the DMDC is an operational support center that stores more than 60 million military, civilian, contractor, family member, retiree, and veteran records used to authorize benefits and entitlements, as well as training, financial, and other data for the U.S. Department of Defense (DoD). It also operates DoD personnel programs and conducts research and analysis as directed by the Office of the Secretary of Defense (OUSD).

This incident follows another massive data breach claimed by the ShinyHunters extortion gang, who breached the FBI's FBIjobs.gov site using an Oracle PeopleSoft zero-day. ShinyHunters claimed to have stolen several terabytes of data (including names, Social Security numbers, home addresses, and assignments) belonging to "almost ALL FBI Agents," including employee records belonging to members of the FBI Remote Operations Unit, a team involved in hacking operations.

§

Analysis

Why This Matters

  • The breach exposes sensitive personal data of millions of current and former military personnel, increasing risks of identity theft and targeted phishing.
  • The extended duration of the breach (October 2025 to July 2026) raises questions about the Pentagon's cybersecurity monitoring and response capabilities.
  • This incident underscores the vulnerability of critical government systems, following a similar breach at the FBI's hiring portal.

Background

The Defense Manpower Data Center (DMDC) was established in 1974 to serve as the central repository for personnel data across the U.S. Department of Defense. It stores records for over 60 million individuals, including active-duty service members, reservists, retirees, civilians, contractors, and family members. The center supports numerous government agencies with benefits, entitlements, and personnel management. This breach is part of a troubling pattern of cyberattacks targeting federal agencies, with the ShinyHunters extortion gang having recently claimed a breach of FBI systems.

Key Perspectives

Affected military personnel: Those impacted face potential misuse of their Social Security numbers and other personal details, with the Pentagon offering only 12 months of free credit monitoring despite the sensitivity of the data. Pentagon and DMDC officials: They have initiated incident response actions and are working to enhance cybersecurity posture, but the nearly year-long undetected access indicates significant shortcomings. Cybersecurity experts and critics: The prolonged breach period and the exploitation of a file-sharing vulnerability highlight systemic weaknesses in federal IT security, especially given the high-value nature of the data.

What to Watch

  • Whether any group claims responsibility for this specific breach, and if the stolen data appears on criminal forums or is used for extortion.
  • The outcome of any internal or external investigations into how the vulnerability was exploited and why it went undetected for so long.
  • Potential congressional hearings or policy changes regarding cybersecurity requirements for defense contractors and federal agencies.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.