A data breach notification letter sent to affected individuals and shared on Reddit confirms that unauthorized users exploited a security vulnerability in an unspecified file-sharing system to access DMDC records over a nine-month period. The exposed data, which was stored unencrypted, includes names, Social Security numbers, dates of birth, sex, race, and detailed military service information. The Pentagon has not publicly identified the attackers or how the vulnerability was discovered.
According to a U.S. defense official, DMDC remediated the vulnerability upon discovery. The official stated: "A Defense Manpower Data Center information system experienced unauthorized access of personally identifiable information by a small number of unauthorized users between October 2025 and July 2026." The Pentagon added that there is no evidence the data has been misused, though officials did not explain how that conclusion was reached.
The breach affects approximately 2.8 million living individuals and nearly 300,000 deceased individuals. DMDC serves as the Pentagon's central repository for personnel records, maintaining over 60 million records covering active-duty service members, reservists, civilian employees, contractors, retirees, veterans, and military family members. The unit also manages identity credentials such as smart cards and passwords used to access Pentagon systems and facilities. Its website states: "We make sure that the right people get access and the wrong people don't: security of identity information is paramount."
The DMDC breach is the latest in a series of major thefts of federal personnel data. Earlier in September, the ShinyHunters hacking group stole personal information from the FBI, including records of most agents and staffers. That incident has been described as a counterintelligence disaster due to the risk of foreign governments using the data to target or coerce federal workers. ShinyHunters has stated it will not release the stolen FBI data publicly. It remains unclear whether the DMDC and FBI breaches are related.
Because the compromised DMDC data includes job details and roles, the breach could expose the identities of personnel in sensitive national security positions. While the absence of immediate misuse is encouraging, security experts warn that stolen data may be held for later exploitation, such as targeted phishing or blackmail campaigns.