SecurityDeveloping

Pentagon breach: millions of military personnel notified as unencrypted personnel records stolen in months-long hack

Attack on Defense Manpower Data Center exposed Social Security numbers, job details and service history for roughly 3 million individuals

By LineZotpaper
Published
Updated
Read Time3 min
Sources2 outlets
The U.S. Department of Defense is notifying millions of current and former military personnel that their personal information was stolen in a months-long breach of the Pentagon's central personnel database, with stolen records including unencrypted Social Security numbers, dates of birth, and job assignments. The breach of the Defense Manpower Data Center (DMDC), which went undetected from October 2025 through July 2026, mirrors the recent theft of FBI agents' personal data identified by the ShinyHunters hacking group.

A data breach notification letter sent to affected individuals and shared on Reddit confirms that unauthorized users exploited a security vulnerability in an unspecified file-sharing system to access DMDC records over a nine-month period. The exposed data, which was stored unencrypted, includes names, Social Security numbers, dates of birth, sex, race, and detailed military service information. The Pentagon has not publicly identified the attackers or how the vulnerability was discovered.

According to a U.S. defense official, DMDC remediated the vulnerability upon discovery. The official stated: "A Defense Manpower Data Center information system experienced unauthorized access of personally identifiable information by a small number of unauthorized users between October 2025 and July 2026." The Pentagon added that there is no evidence the data has been misused, though officials did not explain how that conclusion was reached.

The breach affects approximately 2.8 million living individuals and nearly 300,000 deceased individuals. DMDC serves as the Pentagon's central repository for personnel records, maintaining over 60 million records covering active-duty service members, reservists, civilian employees, contractors, retirees, veterans, and military family members. The unit also manages identity credentials such as smart cards and passwords used to access Pentagon systems and facilities. Its website states: "We make sure that the right people get access and the wrong people don't: security of identity information is paramount."

The DMDC breach is the latest in a series of major thefts of federal personnel data. Earlier in September, the ShinyHunters hacking group stole personal information from the FBI, including records of most agents and staffers. That incident has been described as a counterintelligence disaster due to the risk of foreign governments using the data to target or coerce federal workers. ShinyHunters has stated it will not release the stolen FBI data publicly. It remains unclear whether the DMDC and FBI breaches are related.

Because the compromised DMDC data includes job details and roles, the breach could expose the identities of personnel in sensitive national security positions. While the absence of immediate misuse is encouraging, security experts warn that stolen data may be held for later exploitation, such as targeted phishing or blackmail campaigns.

§

Analysis

Why This Matters

  • The breach exposes millions of military and civilian personnel to identity theft and targeted social engineering, with Social Security numbers and detailed service histories now in unknown hands.
  • The compromise of job assignments and security clearances poses a direct threat to national security, potentially enabling adversaries to identify and target individuals in sensitive roles.
  • This incident follows the FBI breach, raising concerns about systemic vulnerabilities in federal personnel record-keeping and the government's ability to detect intrusions over extended periods.

Background

DMDC is the Department of Defense's central identity management and personnel records unit, holding over 60 million records that determine benefits, entitlements, and access credentials for service members, civilians, contractors, and family members. The breach occurred between October 2025 and July 2026, with the vulnerability in a file-sharing system apparently going undetected for months. The Pentagon has not disclosed whether the same vulnerability or attacker group is connected to the recent FBI breach, in which ShinyHunters stole personal data of most agents. Historically, large-scale government personnel data breaches include the 2015 Office of Personnel Management hack that affected over 21 million individuals.

Key Perspectives

Affected military and civilian personnel: Facing long-term risks of identity theft, phishing attacks, and possible targeting by foreign intelligence services if their job roles or security clearances are known to adversaries. U.S. Department of Defense and DMDC: Emphasizing that the vulnerability was patched immediately upon discovery and that no data misuse has been detected, while reassuring that identity security is a top priority. Critics and security experts: Pointing to the prolonged undetected access and the use of unencrypted storage as signs of inadequate cyber defenses, and warning that threat actors often delay exploiting stolen data to avoid detection.

What to Watch

  • Whether any foreign government or criminal group claims responsibility or attempts to weaponize the stolen data.
  • Congressional hearings or directives demanding reforms to Pentagon cybersecurity practices and encrypted storage for personnel records.
  • Potential lawsuits from affected individuals or class-action claims against the Department of Defense for failing to protect sensitive data.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.