← All stories
● Covered by 4 sources · 4 reportsHigh impact4 negative

Pentagon Personnel Agency Data Breach Exposes 3 Million Records

🔄 Updated 1d ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • DMDC data breach affected 3 million people
  • Unauthorized access to file-sharing server for 9 months
  • Exposed data includes Social Security numbers and PII
  • Vulnerability discovered in July 2026, patched immediately
  • Breach affected 2.76 million living personnel and 294,000 deceased individuals.
  • Exposed data included job details of military and civilian personnel.
  • No evidence of misuse of compromised data has been found yet.
  • Breach occurred between October 2025 and mid-July 2026.
  • Exposed data included name, date of birth, sex, race, and military service information.
  • Personnel records were unencrypted.
  • Breach affected approximately 2.8 million living individuals and 300,000 deceased individuals.
  • DMDC is notifying military personnel about the breach.
  • Hackers exploited a vulnerability in the DMDC's file-sharing systems.
  • Stolen data includes contact information.
  • DMDC immediately initiated incident response actions upon discovery.

Data Breach Details

The US Defense Manpower Data Center (DMDC), responsible for maintaining Pentagon personnel records, has begun notifying individuals about a data breach. Unauthorized users gained access to one of its file-sharing servers for approximately nine months, from October 2025 until July 2026.

The vulnerability in the DMDC file-sharing system was discovered on July 16, 2026. DMDC immediately updated and restored the system after patching the vulnerability. The specific file-sharing product and vulnerability details were not disclosed in the notification letter.

Affected Individuals and Information

The breach impacted 2.76 million living individuals and 294,000 deceased individuals, totaling around 3 million people. The exposed records varied by individual but included sensitive personal identifiable information (PII) such as Social Security numbers, names, dates of birth, contact details, demographic data, and military occupational specialties.

DMDC has stated that there are currently no indications of misuse of the accessed information. The agency holds at least 60 million records covering military and civilian personnel, contractors, family members, retirees, and veterans.

Response and Investigation

Upon discovering the vulnerability, DMDC initiated privacy and cybersecurity incident response actions. The identity of the attackers remains unknown, and no cybercrime group has publicly claimed responsibility for the attack on DMDC.

The incident highlights ongoing challenges in securing sensitive government data, particularly given the extensive personal information maintained by agencies like DMDC.

Updates

🕒 2026-10-01 · new reporting from BleepingComputer
  • DMDC is notifying military personnel about the breach.
  • Hackers exploited a vulnerability in the DMDC's file-sharing systems.
  • Stolen data includes contact information.
  • DMDC immediately initiated incident response actions upon discovery.
🕒 2026-09-30 · new reporting from TechCrunch
  • Breach occurred between October 2025 and mid-July 2026.
  • Exposed data included name, date of birth, sex, race, and military service information.
  • Personnel records were unencrypted.
  • Breach affected approximately 2.8 million living individuals and 300,000 deceased individuals.
🕒 2026-09-30 · new reporting from Tom's Hardware
  • Breach affected 2.76 million living personnel and 294,000 deceased individuals.
  • Exposed data included job details of military and civilian personnel.
  • No evidence of misuse of compromised data has been found yet.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The Pentagon's Defense Manpower Data Center (DMDC) is notifying over 3 million military personnel about a data breach that exposed personally identifiable information (PII) including Social Security numbers. Hackers exploited a vulnerability in the DMDC's file-sharing systems between October 2025 and July 2026, compromising records for both living and deceased individuals.

Millions of current and former U.S. military service members and staff had their personal information, including Social Security numbers, exposed in a data breach of the Pentagon’s personnel records system. The breach occurred over several months between October 2025 and mid-July 2026, affecting approximately 2.8 million living individuals and 300,000 deceased individuals. This incident represents a significant compromise of sensitive government data, following other recent breaches of federal worker information.

The U.S. Department of Defense's Defense Manpower Data Center (DMDC) experienced unauthorized access between October 2025 and July 2026, compromising data for nearly 3 million military and civilian personnel. This breach exposed sensitive information, including Social Security numbers and job details, raising concerns about the privacy and national security implications for those affected.

The US Defense Manpower Data Center (DMDC) experienced a data breach exposing personal information for approximately 3 million individuals. Unauthorized users accessed a file-sharing server for nine months, compromising Social Security numbers, names, and other sensitive data.