Breaches · 12h ago
The Defense Manpower Data Center said a monthslong compromise of its network exposed personnel records for 2.8 million living current and former service members. The stolen data included names, Social Security numbers, addresses, sex, race, and occupational specialties, and ShinyHunters claimed responsibility.
The sensitive part is not just identity data. Job titles and specialties tell an outsider who does what inside the military, so a foreign intelligence service can sort the haul by value and focus on people tied to sensitive missions rather than treating every record the same.
For defense and government systems that hold personnel files, this is a reminder that role metadata can be as useful as an SSN to an adversary. The breach is an intelligence targeting problem as much as a privacy one, and the exposed fields may continue to matter even after account and password cleanup.
1 source covering this story
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
It has been a bad month for federal government cybersecurity.
Part of the PlainSec briefing for 2026-10-02