Data Breaches

DMDC Breach Exposes Military Identity Data at Scale

The Defense Department confirmed a breach at the Defense Manpower Data Center that exposed records on just over 3 million people, including about 294,000 who are deceased. Unauthorised access went unnoticed for about nine months, from October 2025 to July 16, 2026, before the file-sharing flaw was found and patched.

The files were left unencrypted, so anyone who got into the file-sharing system could read Social Security numbers, names, birth dates, contact details, and in some cases job information directly. That makes this a data-exposure event, not a decryption event, and the job details make the records useful for long-tail fraud, impersonation, and more convincing spear-phishing against military communities.

The exposure sits at a core personnel repository, so the lasting risk is not limited to the people named in the breach notice; it also reaches contractors, retirees, families, and the deceased whose identities can still be abused in claims and targeting. The absence of detected misuse so far does not shrink that risk much after nine months of undetected access.

2 sources · 8h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-01

Every edition of this story: DMDC Breach Exposes Military Identity Data at Scale

More from today