Skip to content
Data breachContained

Pentagon's Defense Manpower Data Center breach exposes sensitive data on more than three million people

The U.S. Defense Manpower Data Center said attackers exploited a file-sharing system flaw to access unencrypted data, including Social Security numbers, on more than three million people.

Victim
Defense Manpower Data Center
records
3.1M

On 29 September 2026, it emerged that the U.S. Defense Manpower Data Center (DMDC) โ€” the Pentagon agency that maintains one of the Department of Defense's main repositories of personnel records, covering active-duty and reserve troops, civilian employees, contractors, retirees, veterans and military family members โ€” had notified more than three million people that their sensitive personal information was accessed in a months-long breach. DMDC holds upwards of 60 million records, making it one of the most consequential personnel data stores in the U.S. government.

According to the agency's notification, a small number of unauthorized users exploited a security vulnerability in a DMDC file-sharing system to access files between October 2025 and mid-July 2026. DMDC said it discovered the flaw on 16 July 2026, immediately updated the file-sharing system to patch it and restored the service. The breach affected roughly 2.76 million living individuals and about 294,000 deceased people, for a total of more than three million.

What was exposed

The compromised records varied by individual but included Social Security numbers alongside names, dates of birth, contact details, demographic data and military occupational specialties. Multiple reports noted that the affected data was stored unencrypted, compounding the exposure. The Defense Department said it had no indications that the accessed information had been misused at the time of notification.

Response and significance

The Department of Defense is offering affected individuals one year of credit monitoring and identity-restoration services. No cybercrime group publicly claimed responsibility for the intrusion. Because DMDC underpins identity and benefits systems across the U.S. military, a breach of unencrypted Social Security numbers and service details for millions of current and former personnel carries heightened risk of identity theft and targeted social engineering. With the vulnerability patched and the system restored but the investigation continuing, the incident's status was recorded as contained.

Timeline

  1. Unauthorized users begin accessing files through a vulnerable DMDC file-sharing system (access continues until mid-July 2026).

  2. DMDC discovers the security vulnerability, patches the file-sharing system and restores it.

  3. DMDC begins mailing breach-notification letters to affected individuals.

  4. The breach is widely reported, confirming more than three million people were affected.

Sources

  1. securityweek.comhttps://www.securityweek.com/pentagon-personnel-agency-data-breach-impacts-3-million-people/
  2. techcrunch.comhttps://techcrunch.com/2026/09/30/hackers-stole-millions-of-us-military-personnel-records-during-months-long-data-breach
  3. federalnewsnetwork.comhttps://federalnewsnetwork.com/defense-main/2026/09/more-than-3-million-people-affected-by-military-data-breach/
  4. privacyguides.orghttps://www.privacyguides.org/news/2026/09/29/highly-sensitive-data-of-3-million-in-the-people-in-the-pentagons-system-accessed-by-unauthorized-users/

Related incidents

Data breachContained

Florida DMV confirms breach of DAVID driver database via compromised law-enforcement account

Florida's Department of Highway Safety and Motor Vehicles confirmed that attackers used a compromised law-enforcement account to breach its DAVID driver database, as the ShinyHunters extortion group claimed to have stolen more than 200,000 driver records.

Victim
Florida Department of Highway Safety and Motor Vehicles
Records
200.0K