Pentagon personnel data breach exposes 2.8 million current and former U.S. military personnel
Quick Look
The U.S. Defense Manpower Data Center notified millions of current and former military personnel that their personal data, including Social Security numbers and service details, was stolen in a months-long breach of an unencrypted file-sharing system between October 2025 and July 2026, affecting approximately 2.8 million living individuals and 300,000 deceased persons.
AI-generated summary
Why It Matters
The breach follows a pattern of cyberattacks on U.S. federal agencies, including the 2015 Office of Personnel Management breach affecting over 22 million employees and a recent FBI breach attributed to the ShinyHunters group.
The U.S. government is reportedly alerting millions of current and former U.S. military service members and staff that their personal information was stolen during a months-long breach of the Pentagon’s personnel records, the latest in a spate of thefts involving federal workers’ data in recent months.
A data breach notification from the Defense Manpower Data Center (DMDC) shared on Reddit says that several unauthorized users exploited a security vulnerability in an unspecified file-sharing system over several months between October 2025 and mid-July 2026.
The breach exposed personally identifiable information, including Social Security numbers, alongside a person’s name, date of birth, sex, race, and other information about their military service. The notice says that the personnel records were unencrypted.
According to CNN and Federal News Network, a Pentagon official said the breach affects about 2.8 million living people, and close to 300,000 people who are deceased.
The U.S. military has 1.3 million active service members as of March.
The DMDC may not be widely known to the general public, but serves as one of the Department of Defense’s records-keeping units. The DMDC maintains over 60 million records for U.S. military and civilian staff and their family members to help determine benefits and entitlements, such as healthcare and retirement. The unit also provides a critical service as the military’s “leading identity management provider,” which links active service members, employees, and contractors to credentials, such as smart cards and passwords. These are used to access Pentagon computer systems, buildings, and bases.
“We make sure that the right people get access and the wrong people don’t: security of identity information is paramount,” the DMDC’s website reads.
The Department of Defense, which oversees the DMDC, said it does not have any indication that the information was misused, but did not say how it reached that conclusion. TechCrunch contacted a Pentagon spokesperson to ask if officials had any communications from the hackers, whose identities are not known, but we did not hear back.
This is the latest major breach of federal workers’ personal information in recent months, following a recent breach at the FBI earlier in September attributed to the ShinyHunters hacking group. The hackers told TechCrunch that they had taken the personal information of most of the FBI’s agents and staffers, including applicants. The breach has been billed as a “counterintelligence disaster” amid the risks that a foreign government could obtain and use the information to profile, target, or coerce federal workers into handing over sensitive information.
The ShinyHunters hackers have said that they will not publicly release the stolen FBI data.
Both breaches involving the FBI and the DMDC mirror similar thefts of government personnel records in the past. In 2015, a breach of the U.S. government’s human resources department, known as the Office of Personnel Management, was broadly attributed to China. The theft allowed the hackers to steal the private records of more than 22 million U.S. government employees, many of whom had security clearances.
What to Watch
AI outlook — possibilities, not facts
The Department of Defense will implement enhanced encryption and security measures for the DMDC systems.
Likely · Within weeks
Affected individuals will be offered credit monitoring or identity theft protection services.
Likely · Within months
Open Questions
- What specific file-sharing system was exploited?
- How did the Department of Defense conclude the data was not misused?
- Are there any known communications from the hackers?
- What steps are being taken to secure the DMDC systems?







