Home » Military » Pentagon Personnel Data Breach Exposes Records of Nearly 3.1 million US Military Members

Pentagon Personnel Data Breach Exposes Records of Nearly 3.1 million US Military Members

A months-long Pentagon data breach exposed records of nearly 3.1 million living and deceased US military personnel.
The Pentagon in Arlington, Virginia. Hackers exploited a flaw in a Defense Department file-sharing system from October 2025 to mid-July 2026.

A months-long cyberattack on a US Defense Department personnel system exposed sensitive information linked to nearly 3.1 million current, former and deceased military personnel.

The breach exploited a security weakness in an unidentified file-sharing system between October 2025 and mid-July 2026. The exposed records included Social Security numbers, names, dates of birth, sex, race and information connected to military service.

The Defense Manpower Data Center (DMDC) disclosed the incident in a data breach notification sent to affected individuals.

The notice said unauthorized users accessed the system through a vulnerability in a file-sharing system used to store personnel information. It also stated that the affected personnel records were not encrypted.

Pentagon officials told CNN and Federal News Network that the incident affects about 2.8 million living people. The same figures also include nearly 300,000 deceased individuals. Susan Gough, a Department of Defense spokesperson, confirmed the number but did not provide further details about the intrusion.

The US military has about 1.3 million active-duty service members as of March. The number of people affected by the breach is therefore substantially larger than the current active-duty force. The affected population includes people connected to military service beyond those currently serving.

What The Data Includes

The DMDC is a Defense Department records organization that manages information for military and civilian personnel. Its databases contain more than 60 million records covering service members, civilian employees and their family members. These records help determine access to benefits and services, including healthcare and retirement programs.

The organization also plays an important role in military identity management. It links service members, employees and contractors with credentials such as smart cards and passwords. Those credentials can be used to access Pentagon systems, military facilities and bases.

The breach exposed personally identifiable information, data that can identify an individual. Social Security numbers are among the most sensitive items listed in the notification, along with names, birth dates and other personal details. The exposed records also included information about military service.

READ ALSO: https://modernmechanics24.com/post/china-aviation-brake-tech-jets-evs/

The DMDC says protecting identity information is central to its security role. The agency’s systems help determine who should receive access to government services and computer networks. The incident has therefore raised questions about the protection of personnel information held by a major Defense Department records system.

Investigation Into Attackers

The identities of the unauthorized users remain unknown. The Department of Defense has not disclosed whether the attackers contacted officials, demanded payment or claimed responsibility for the intrusion. Officials also have not publicly identified the file-sharing system involved in the breach.

The Defense Department said it does not indicate that the stolen information has been misused. However, officials have not explained how they reached that assessment or provided evidence showing whether other parties accessed the data. The investigation remains focused on understanding the intrusion and the information that was obtained.

The incident comes after another reported theft involving US government personnel data. In September, hackers associated with the ShinyHunters group claimed they had obtained personal information belonging to FBI agents, employees and applicants. The group told TechCrunch that it would not publicly release the stolen FBI information.

Federal Data Under Pressure

The latest incident follows a long history of attacks targeting US government personnel databases. One of the largest occurred in 2015, when hackers breached the Office of Personnel Management, the federal agency responsible for managing government human resources. The incident exposed records belonging to more than 22 million federal employees and other individuals.

The 2015 breach was broadly attributed to China. The stolen information included sensitive records belonging to many people who held US government security clearances. Such databases can contain information that extends well beyond basic employment details.

The current DMDC incident shows the continuing security challenge faced by government agencies that store large volumes of personal information. A single weakness in a system used to share or store files can expose records belonging to millions of people. For military organizations, protecting such information is also tied to the security of the wider personnel and identity-management system.

The immediate priority will be determining exactly how the attackers entered the system, what information they removed and whether the stolen records have been accessed elsewhere.

Further findings from the investigation may also determine whether additional security measures are needed across Defense Department personnel systems. The incident adds another major case to the growing record of cyberattacks against sensitive US government databases.

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *