A months-long Pentagon data breach reportedly exposed personal records belonging to millions of current and former U.S. military personnel and staff, including Social Security numbers, after attackers exploited a vulnerability in a file-sharing system.
TL;DR
- Unauthorized users reportedly accessed Pentagon personnel records between October 2025 and mid-July 2026.
- Around 2.8 million living people and nearly 300,000 deceased individuals were reportedly affected.
- Exposed information included names, Social Security numbers, birth dates, race, sex, and military-service information.
- The Department of Defense said it has no indication that the stolen information has been misused.
Pentagon Data Breach Exposed Unencrypted Military Personnel Records
The breach affected systems operated by the Defense Manpower Data Center (DMDC), one of the Department of Defense's key personnel record-keeping units.
According to a data breach notification cited in the report, several unauthorized users exploited a vulnerability in an unspecified file-sharing system over a period stretching from October 2025 until mid-July 2026.
The stolen records were reportedly unencrypted.
Information exposed included names, Social Security numbers, dates of birth, sex, race, and details connected to an individual's military service.
A Pentagon official reportedly said approximately 2.8 million living people were affected, alongside close to 300,000 deceased individuals.
The scale is particularly notable because the U.S. military had around 1.3 million active service members as of March, meaning the affected population extends beyond currently serving personnel.
The incident joins a wider series of attacks targeting government systems and sensitive records. TechDogs recently covered an incident where an OpenAI agent breached Australia's Medicare portal, as well as longstanding concerns around vulnerabilities across U.S. government and public-record systems.
Why The DMDC Data Breach Creates A Serious Identity Security Risk
The DMDC maintains more than 60 million records belonging to military personnel, civilian staff, and family members, which are used to determine benefits and entitlements including healthcare and retirement.
Its role goes beyond maintaining personnel files.
The organization also describes itself as the military's “leading identity management provider,” connecting active service members, employees, and contractors with credentials such as passwords and smart cards used to access Pentagon systems, buildings, and military bases.
“We make sure that the right people get access and the wrong people don’t: security of identity information is paramount,” the DMDC's website statement quoted in the report reads.
That makes the exposure particularly sensitive, even though the Department of Defense said it currently has no indication that the stolen information has been misused.
The identities of the attackers remain unknown.
Topics For More Insights
- OpenAI Agent Hacked Australia’s Medicare Portal In First Known Government AI Breach
- Google Says Hackers Used AI Agents To Steal Thousands Of Credentials In Under Six Hours
- CareCloud Hack Exposes Nearly 350,000 Patients’ Sensitive Medical & Financial Records
- US Will Let Private Firms Launch Cyberattacks Under Federal Supervision
Pentagon Breach Follows Other Major US Government Personnel Data Thefts
The Pentagon incident follows another recent breach involving the FBI, where hackers reportedly obtained personal information belonging to agents, staff, and applicants.
It also recalls the much larger 2015 breach of the U.S. Office of Personnel Management, where attackers stole records belonging to more than 22 million government employees, including individuals holding security clearances.
For the latest Pentagon breach, however, several important questions remain unanswered.
The Department of Defense has not publicly identified the attackers or explained how it determined that the stolen information has not been misused. With highly sensitive identity and military-service information reportedly exposed for millions of people, the consequences of the breach may depend on what the attackers ultimately do with the data.

