The U.S. Department of Defense has notified millions of current and former military personnel that their sensitive personal information was compromised during an extended breach of the Pentagon's personnel database. The Defense Manpower Data Center (DMDC), which maintains records for military and civilian staff, disclosed that unauthorized users exploited a security vulnerability in an unspecified file-sharing system over a nine-month window spanning October 2025 through mid-July 2026. The breach affected approximately 2.8 million living individuals and roughly 300,000 deceased persons, representing a significant portion of the U.S. military personnel population, which numbers 1.3 million active service members as of March 2026.
The compromised records contained highly sensitive personally identifiable information critical to both individual identity and national security concerns. Exposed data included Social Security numbers, full names, dates of birth, sex, race, and detailed military service records. Compounding the severity, the personnel records stored in the system were unencrypted, meaning the data was accessible in plain text once hackers gained entry. The DMDC maintains over 60 million total records for military and civilian employees and their family members, using this information to determine benefits and entitlements including healthcare and retirement provisions.
The breach carries particular national security implications because the DMDC functions as the Department of Defense's primary identity management provider. The organization issues and links active service members, civilian employees, and contractors to critical security credentials including smart cards and passwords used to access Pentagon computer systems, buildings, and military bases. The center's mission statement emphasizes that ensuring the right people gain access while blocking unauthorized individuals represents a paramount security function. The compromise of this identity infrastructure raises significant concerns about potential downstream threats to military facility access and system security.
This incident represents the latest in a troubling series of compromises targeting U.S. federal personnel records. In September 2026, the FBI experienced a substantial breach attributed to the ShinyHunters hacking group, which reportedly obtained personal information on most FBI agents, staffers, and applicants. Security analysts characterized the FBI breach as a counterintelligence disaster, citing risks that foreign governments could use stolen personnel data to profile, target, or manipulate federal workers into compromising sensitive information. The ShinyHunters group has indicated it will not publicly release the stolen FBI data, though the breach remains a significant vulnerability. These recent incidents echo the 2015 breach of the Office of Personnel Management, broadly attributed to Chinese operatives, which exposed records on over 22 million U.S. government employees, many holding security clearances.
The Department of Defense stated it has no indication that the stolen information has been misused, though officials did not explain the methodology behind this assessment. The identity of the hackers responsible for the DMDC breach remains unknown, and Pentagon representatives did not respond to inquiries about whether officials had received communications from the attackers. The notice disclosed to affected individuals provides limited detail about the investigation's progress or the specific file-sharing vulnerability exploited. The extended duration of the breach—spanning nine months before discovery—raises questions about detection capabilities and monitoring systems designed to identify unauthorized access to military personnel databases.
Gist is a free AI reader for your browser, iPhone, and Android. Get concise summaries and key takeaways from any article or podcast.
Get Gist — Free