Pentagon personnel data center breach exposes data of about 3 million people

The Defense Manpower Data Center says attackers abused a file-sharing system flaw to access records, including Social Security numbers, of roughly 3 million people between October 2025 and July 2026.

Pentagon personnel data center breach exposes data of about 3 million people

At a glance

  • According to SecurityWeek, unauthorized access to a DMDC file-sharing system lasted from October 2025 until it was discovered on 16 July 2026.
  • About 2.76 million living and 294,000 deceased individuals are affected, according to notification letters.
  • Exposed data includes Social Security numbers, names, dates of birth, contact details, demographic data and military personnel information.
  • No group has claimed the attack; affected people are offered 12 months of credit monitoring with enrollment open until 19 August 2027.

The U.S. Defense Manpower Data Center (DMDC), which maintains the Pentagon's personnel records, has disclosed a data breach affecting about 3 million people, including Social Security numbers and military personnel information. According to SecurityWeek, attackers abused a vulnerability in a DMDC file-sharing system and had access to files for roughly nine months before the intrusion was discovered.

What happened

According to SecurityWeek, which cited a notification letter dated 18 September 2026 that a recipient shared on Reddit as well as CNN reporting, unauthorized users had access to DMDC files from October 2025 until mid-July 2026. The breach was discovered on 16 July 2026.

The letter states that "DMDC immediately updated the file sharing system to patch the vulnerability and the system was restored," SecurityWeek reported. Neither the file-sharing product nor the specific vulnerability has been disclosed.

BleepingComputer, which described the affected system as the Pentagon's human resources management system, reported that DMDC initiated incident response actions in line with Office of Management and Budget and department guidelines.

Who is affected

According to the reports, the breach affects about 2.76 million living individuals and 294,000 deceased individuals. The exposed information varies by person but includes:

  • Social Security numbers
  • names and dates of birth
  • contact details
  • demographic data such as sex and race
  • military personnel information, including occupational specialties

DMDC, founded in 1974, describes itself as maintaining more than 60 million records covering military personnel, civilians, contractors, family members, retirees and veterans, according to BleepingComputer.

Attribution

No known cybercrime group has claimed responsibility for the attack, and it remains unclear who is behind it. According to SecurityWeek, the department said it does not currently have any indications that the accessed information has been misused.

The long dwell time and the sensitivity of the data make the incident notable. Records combining Social Security numbers with service details can be valuable both for identity fraud and for intelligence targeting of military personnel.

What to do

The Pentagon is offering affected individuals 12 months of free credit monitoring through IDX, with an enrollment deadline of 19 August 2027, according to BleepingComputer. Recipients of notification letters should enroll, consider placing a credit freeze with the major credit bureaus, and watch for phishing messages that reference their military service or personnel records.

For organizations, the incident is another example of file-sharing and file-transfer systems being used as an entry point for large-scale data theft. Such systems should be patched promptly, kept off the public internet where possible, and monitored for unusual bulk downloads.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.