Breaches · 7h ago
The Defense Department confirmed a breach at the Defense Manpower Data Center that exposed records on just over 3 million people, including about 294,000 who are deceased. Unauthorised access went unnoticed for about nine months, from October 2025 to July 16, 2026, before the file-sharing flaw was found and patched.
The files were left unencrypted, so anyone who got into the file-sharing system could read Social Security numbers, names, birth dates, contact details, and in some cases job information directly. That makes this a data-exposure event, not a decryption event, and the job details make the records useful for long-tail fraud, impersonation, and more convincing spear-phishing against military communities.
The exposure sits at a core personnel repository, so the lasting risk is not limited to the people named in the breach notice; it also reaches contractors, retirees, families, and the deceased whose identities can still be abused in claims and targeting. The absence of detected misuse so far does not shrink that risk much after nine months of undetected access.
2 sources covering this story
Hackers stole Pentagon personnel records of over 3 million people
The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025.
Pentagon personnel database breach exposes personal data of millions
The US Department of Defense has confirmed a breach at one of its main repositories of personnel information, the Defense Manpower Data Center (DMDC), that has exposed the sensitive details of just over three million people.
Part of the PlainSec briefing for 2026-10-01