Breaking
FRDemonstration in front of the Montpellier court against the mayor of Béziers Robert MénardUSYankees' Schlittler and Rice dominate Red Sox in Wild Card Game 1RUFlydubai has suspended flights to Israel following an incident on board a Dubai-Tel Aviv flightEUUkraine Faces $27 Billion Defense Funding Gap as Russia Intensifies AttacksARSaudi Arabia, Oman, the Emirates, and Qatar qualified for the 27th Gulf semi-finals after the elimination of Bahrain, Yemen, Iraq, and Kuwait.INTLNetanyahu praises Indian pilot who subdued attacker on Flydubai flightTRKonyaspor-Palestine National Team match was described as an event that won humanityITDiana Bianchedi resigns as head of the National delegation after Minister Abodi's statementsINTLMicron Reports Strong Quarterly Results Amid AI-Driven Demand SurgeITBreakthrough in the investigation into ricin poisoning in Pietracatella: Gianni Di Vita questioned and a confidential witness listened toFRDemonstration in front of the Montpellier court against the mayor of Béziers Robert MénardUSYankees' Schlittler and Rice dominate Red Sox in Wild Card Game 1RUFlydubai has suspended flights to Israel following an incident on board a Dubai-Tel Aviv flightEUUkraine Faces $27 Billion Defense Funding Gap as Russia Intensifies AttacksARSaudi Arabia, Oman, the Emirates, and Qatar qualified for the 27th Gulf semi-finals after the elimination of Bahrain, Yemen, Iraq, and Kuwait.INTLNetanyahu praises Indian pilot who subdued attacker on Flydubai flightTRKonyaspor-Palestine National Team match was described as an event that won humanityITDiana Bianchedi resigns as head of the National delegation after Minister Abodi's statementsINTLMicron Reports Strong Quarterly Results Amid AI-Driven Demand SurgeITBreakthrough in the investigation into ricin poisoning in Pietracatella: Gianni Di Vita questioned and a confidential witness listened to
BackPentagon personnel data breach exposes 2.8 million current and former U.S. military personnel
Pentagon personnel data breach exposes 2.8 million current and former U.S. military personnel
BREAKING
TechCrunch1 hour agoTech2 min readUnited States

Pentagon personnel data breach exposes 2.8 million current and former U.S. military personnel

Quick Look

The U.S. Defense Manpower Data Center notified millions of current and former military personnel that their personal data, including Social Security numbers and service details, was stolen in a months-long breach of an unencrypted file-sharing system between October 2025 and July 2026, affecting approximately 2.8 million living individuals and 300,000 deceased persons.

AI-generated summary

Why It Matters

The breach follows a pattern of cyberattacks on U.S. federal agencies, including the 2015 Office of Personnel Management breach affecting over 22 million employees and a recent FBI breach attributed to the ShinyHunters group.

Font size

The U.S. government is reportedly alerting millions of current and former U.S. military service members and staff that their personal information was stolen during a months-long breach of the Pentagon’s personnel records, the latest in a spate of thefts involving federal workers’ data in recent months.

A data breach notification from the Defense Manpower Data Center (DMDC) shared on Reddit says that several unauthorized users exploited a security vulnerability in an unspecified file-sharing system over several months between October 2025 and mid-July 2026.

The breach exposed personally identifiable information, including Social Security numbers, alongside a person’s name, date of birth, sex, race, and other information about their military service. The notice says that the personnel records were unencrypted.

According to CNN and Federal News Network, a Pentagon official said the breach affects about 2.8 million living people, and close to 300,000 people who are deceased.

The U.S. military has 1.3 million active service members as of March.

The DMDC may not be widely known to the general public, but serves as one of the Department of Defense’s records-keeping units. The DMDC maintains over 60 million records for U.S. military and civilian staff and their family members to help determine benefits and entitlements, such as healthcare and retirement. The unit also provides a critical service as the military’s “leading identity management provider,” which links active service members, employees, and contractors to credentials, such as smart cards and passwords. These are used to access Pentagon computer systems, buildings, and bases.

“We make sure that the right people get access and the wrong people don’t: security of identity information is paramount,” the DMDC’s website reads.

The Department of Defense, which oversees the DMDC, said it does not have any indication that the information was misused, but did not say how it reached that conclusion. TechCrunch contacted a Pentagon spokesperson to ask if officials had any communications from the hackers, whose identities are not known, but we did not hear back.

This is the latest major breach of federal workers’ personal information in recent months, following a recent breach at the FBI earlier in September attributed to the ShinyHunters hacking group. The hackers told TechCrunch that they had taken the personal information of most of the FBI’s agents and staffers, including applicants. The breach has been billed as a “counterintelligence disaster” amid the risks that a foreign government could obtain and use the information to profile, target, or coerce federal workers into handing over sensitive information.

The ShinyHunters hackers have said that they will not publicly release the stolen FBI data.

Both breaches involving the FBI and the DMDC mirror similar thefts of government personnel records in the past. In 2015, a breach of the U.S. government’s human resources department, known as the Office of Personnel Management, was broadly attributed to China. The theft allowed the hackers to steal the private records of more than 22 million U.S. government employees, many of whom had security clearances.

What to Watch

AI outlook — possibilities, not facts

  • The Department of Defense will implement enhanced encryption and security measures for the DMDC systems.

    Likely · Within weeks

  • Affected individuals will be offered credit monitoring or identity theft protection services.

    Likely · Within months

Open Questions

  • What specific file-sharing system was exploited?
  • How did the Department of Defense conclude the data was not misused?
  • Are there any known communications from the hackers?
  • What steps are being taken to secure the DMDC systems?

Related Topics

This article was originally published by TechCrunch.

Related Stories

Reddit to end RSS feed support on November 13, public API by March 2027
Developing·

Reddit to end RSS feed support on November 13, public API by March 2027

Reddit announced it will discontinue RSS feed support on November 13 and shut down its public API by March 2027, citing RSS as a common surface for large-scale scraping and automated abuse. The move affects moderators, developers, researchers, and AI tools reliant on open access to Reddit's content, with no direct replacement for external RSS use, as the company prioritizes data control amid growing AI licensing revenue.

TechCrunch
2 min read
Meta Denies AI Agent Muse Accessed Private Messages Without User Consent
Developing·

Meta Denies AI Agent Muse Accessed Private Messages Without User Consent

Meta refutes claims by journalist Jason Aten that its AI agent Muse read his private messages without permission, stating the feature requires explicit user opt-in via Full Disk Access and Messages connector. Despite denials, skepticism remains due to Meta's history of data privacy issues, including a recent New Mexico jury verdict related to the Cambridge Analytica scandal. Meta executives emphasize multiple permission steps and macOS protections prevent unauthorized access, even if Aten's account of events is disputed.

TechCrunch
2 min read
Instinct AI startup launches product recommendations feature, faces user backlash
Developing·

Instinct AI startup launches product recommendations feature, faces user backlash

Instinct AI launched Instinct Selections, a feature offering human-curated product recommendations in dining, travel, and shopping, but users report unsolicited suggestions feel like spam. Founder Noah Shinn announced the feature on X, emphasizing partnerships with local experts to differentiate from AI-only suggestions. Criticism came from users including Shruti Gandhi of Array VC and entrepreneur Andrew Yeung, who found the pushes irrelevant and off-putting. The feature follows a $1 billion Series C round valuing Instinct at $10 billion, with Shinn noting the platform handles near $1 billion in annual transactions, over half travel-related.

TechCrunch
2 min read
More on this topicpentagon