Pentagon Data Breach Exposes 2.8 Million Military Personnel Records
Pentagon breach exposed unencrypted personal records, including Social Security numbers, of 2.8 million living and nearly 300,000 deceased people nationwide.
Summary
Several unauthorized users exploited a vulnerability in an unspecified file-sharing system from October 2025 to mid-July 2026, stealing unencrypted Defense Manpower Data Center records. The breach affects about 2.8 million living people and close to 300,000 deceased people, exposing names, Social Security numbers, birth dates, sex, race and military service information. The U.S. military had 1.3 million active members as of March. The Department of Defense says it has no indication of misuse but has not explained that assessment. The attackers remain unidentified, and the Pentagon has not disclosed whether they contacted officials.
DMDC maintains more than 60 million records for military and civilian personnel and their families, determining healthcare and retirement entitlements while linking service members, employees and contractors to smart cards and passwords used for Pentagon systems, buildings and bases. The breach follows a September FBI intrusion attributed to ShinyHunters, which claimed it stole data on most agents, staff and applicants but said it would not publish it. That theft raised concerns foreign governments could profile, target or coerce federal workers. In 2015, hackers widely linked to China stole records on more than 22 million government employees, many holding security clearances, from the Office of Personnel Management.
Positives
- The U.S. government is notifying millions of current and former service members and staff that their records were stolen.
- The Department of Defense says it has no indication that the stolen DMDC information has been misused.
- ShinyHunters says it will not publicly release the FBI personnel data stolen in September.
Risks & concerns
- About 2.8 million living people and nearly 300,000 deceased people are affected by the DMDC breach.
- Social Security numbers, names, birth dates, sex, race and military service details were stored without encryption.
- Unauthorized users retained access to the vulnerable file-sharing system from October 2025 until mid-July 2026.
- DMDC identity systems connect personnel and contractors to credentials used for Pentagon computers, buildings and military bases.
- The Department of Defense has not explained why it believes the stolen information has not been misused.
- The FBI and DMDC breaches create risks that foreign governments could profile, target or coerce federal workers.