Pentagon personnel breach exposed data of about 3.05M
The Pentagon’s DMDC reported unencrypted personal data for about 2.76 million living people and 294,000 deceased were exposed, including Social Security numbers, after unauthorized file‑server access.
Unauthorized users accessed a Defense Manpower Data Center file‑sharing server from about October 2025 until a security vulnerability was discovered and patched on July 16, 2026. The exposure affected roughly 2.76 million living people and 294,000 deceased individuals and included Social Security numbers.
Notification letters dated Sept. 18 were sent after the vulnerability was identified. The notification notes the file‑sharing system was updated to patch the vulnerability and the system was restored. The agency did not name the file‑sharing product or describe the technical flaw.
DMDC’s review found a small number of unauthorized users accessed files on a server that contained unencrypted personally identifiable information. The records exposed varied by person and included Social Security numbers, names, dates of birth, contact information, demographic data and military occupational specialties. The agency reports no indications of misuse of the accessed information at this time.
A Defense Department official provided the counts of affected individuals. Public records show DMDC held at least 60 million records in fiscal year 2024 covering military and civilian personnel, contractors, family members, retirees and veterans. The agency did not specify which categories of records were involved in this incident.
DMDC opened privacy and cybersecurity incident‑response actions and has begun notifying impacted people. The agency has not identified who was behind the unauthorized access, and no criminal group has claimed responsibility for the intrusion.







