Pentagon personnel database breach exposes personal data of millions

2 hours ago 3

The US Department of Defense has confirmed a breach at one of its main repositories of personnel information, the Defense Manpower Data Center (DMDC), that has exposed the sensitive details of just over three million people.

According to media reports, some 2.76 million people are impacted by the breach, as well as a further 294,000 who are now deceased.

Unauthorised users are said to have accessed files between October 2025 and 16 July 2026 without anyone noticing. It was only after nine months that a vulnerability in a file-sharing system was discovered and patched by the DMDC.

The unencrypted files contained Social Security numbers, names, birth dates, contact details, and other military personnel data including - in some cases - details of the jobs individuals held.

The Pentagon has tried to reassure those impacted, saying that it has seen no evidence that the data has been misused to date, and offering 12 months' worth of identity protection and credit monitoring to victims.

What is perhaps important for everyone to realise, however, is that "not seen any evidence of misuse" is not the same as "no misuse." That point hits particularly hard when you consider that the hackers appear to have had nine months' undetected access to the sensitive data.

What we should be grateful for is that the breach was not even larger. The DMDC holds more than 60 million records on military troops, civilian employees, contractors, retirees, veterans and families of those who have served in the forces. So, the fact that only around one in twenty of the records held by the DMDC were exposed by the breach is some consolation.

Breaches like this matter because the combination of Social Security numbers, names, and dates of birth make up the bread and butter of any self-respecting fraudster.

But the fact that job details were also included makes this more than a routine breach for the US Department of Defense. As CNN reports, sensitive data like that can be a goldmine for foreign intelligence agencies and hackers who are looking to track or extort US military personnel. Knowing who does what in the US military can help make a spear-phishing attack far more convincing.

Unfortunately, this is not the first time that hackers have stolen the Pentagon's data. For instance, back in 2008, the Department of Defense was infiltrated by the hackers after a malware-laden USB stick was plugged into a laptop at a US base in the Middle East, resulting in a 14 month clean-up.

Personnel data, of course, has also been a target before. For example, in 2015 the Office of Personnel Management breach exposed the records of around 21.5 million people, including security clearance background checks. That hack was widely blamed on China.

The news of the Pentagon's latest data breach comes as the FBI warns its own employees about a separate breach of its FBIJobs.gov portal. The ShinyHunters hacking group has claimed credit for the hack and threatened to publish staff details including... you guessed it... Social Security numbers.

Read Entire Article