The US Defense Manpower Data Center (DMDC), responsible for maintaining Pentagon personnel records, has begun notifying individuals about a data breach. Unauthorized users gained access to one of its file-sharing servers for approximately nine months, from October 2025 until July 2026.
The vulnerability in the DMDC file-sharing system was discovered on July 16, 2026. DMDC immediately updated and restored the system after patching the vulnerability. The specific file-sharing product and vulnerability details were not disclosed in the notification letter.
The breach impacted 2.76 million living individuals and 294,000 deceased individuals, totaling around 3 million people. The exposed records varied by individual but included sensitive personal identifiable information (PII) such as Social Security numbers, names, dates of birth, contact details, demographic data, and military occupational specialties.
DMDC has stated that there are currently no indications of misuse of the accessed information. The agency holds at least 60 million records covering military and civilian personnel, contractors, family members, retirees, and veterans.
Upon discovering the vulnerability, DMDC initiated privacy and cybersecurity incident response actions. The identity of the attackers remains unknown, and no cybercrime group has publicly claimed responsibility for the attack on DMDC.
The incident highlights ongoing challenges in securing sensitive government data, particularly given the extensive personal information maintained by agencies like DMDC.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Pentagon's Defense Manpower Data Center (DMDC) is notifying over 3 million military personnel about a data breach that exposed personally identifiable information (PII) including Social Security numbers. Hackers exploited a vulnerability in the DMDC's file-sharing systems between October 2025 and July 2026, compromising records for both living and deceased individuals.
Millions of current and former U.S. military service members and staff had their personal information, including Social Security numbers, exposed in a data breach of the Pentagon’s personnel records system. The breach occurred over several months between October 2025 and mid-July 2026, affecting approximately 2.8 million living individuals and 300,000 deceased individuals. This incident represents a significant compromise of sensitive government data, following other recent breaches of federal worker information.
The U.S. Department of Defense's Defense Manpower Data Center (DMDC) experienced unauthorized access between October 2025 and July 2026, compromising data for nearly 3 million military and civilian personnel. This breach exposed sensitive information, including Social Security numbers and job details, raising concerns about the privacy and national security implications for those affected.
The US Defense Manpower Data Center (DMDC) experienced a data breach exposing personal information for approximately 3 million individuals. Unauthorized users accessed a file-sharing server for nine months, compromising Social Security numbers, names, and other sensitive data.