Morning Edition · №
Cybersecurity WASHINGTON

Hackers Quietly Accessed Pentagon Personnel Records for Nine Months, Exposing Data on 3 Million People

A vulnerability in a Defense Department personnel system let unauthorized users view Social Security numbers and service records for nearly a year before anyone noticed.

Hackers Quietly Accessed Pentagon Personnel Records for Nine Months, Exposing Data on 3 Million People
The Pentagon, photographed in 2008. — Photograph: David B. Gleason / Wikimedia Commons, CC BY-SA 2.0
SHARE X f in ⧉

The Pentagon has spent the past two and a half weeks notifying millions of current and former service members, civilian employees and their families that hackers had access to a personnel database for roughly nine months before anyone noticed. The breach, confirmed in notices sent beginning Sept. 18, ranks among the largest exposures of military personal data in years.

At issue is the Defense Manpower Data Center, or DMDC, a Pentagon system that functions as the central repository for identity and benefits records covering active-duty troops, reservists, veterans, retirees, contractors and military family members. According to the department's breach notice, unauthorized users accessed personally identifiable information belonging to roughly 2.76 million living people and 294,000 deceased former personnel or their dependents — a total of just over 3 million records. Exposed data included Social Security numbers, full names, birth dates, contact information and details of the jobs people held within the Defense Department.

A Vulnerability Open for Nine Months

The Pentagon says a "small number of unauthorized users" exploited a flaw in a DMDC file-sharing system to view the records, which were stored unencrypted. That access window ran from October 2025 until July 16, 2026, when the vulnerability was discovered and patched the same day. It then took the department roughly two months to notify affected individuals, with letters going out starting Sept. 18 and the breach becoming widely reported soon after. The Pentagon has not said how the intrusion was ultimately detected, who was behind it, or whether specific individuals were targeted.

DMDC's footprint makes the incident notable beyond its raw numbers: the system holds more than 60 million personnel records in total, serving, in its own description, as a "one, central access point for information and assistance" for the military community. In its notice, the department said it has found no evidence so far that the stolen data has been misused, and that it is "taking appropriate action to assess and enhance the cybersecurity posture" of the system.

Part of a Difficult Year for Government Networks

The disclosure lands amid a string of breaches at federal agencies and their contractors. Just a week earlier, the hacking group ShinyHunters claimed responsibility for breaching FBI systems and stealing data tied to agents and job applicants, one of several intrusions this year that have put pressure on agencies to modernize decades-old data infrastructure. Unlike many recent breaches tied to ransomware gangs or state-linked actors, the Pentagon has not publicly attributed the DMDC intrusion to any particular group.

For affected individuals, the department is offering a year of identity-theft monitoring and restoration services through the vendor IDX, and has pointed service members toward free credit monitoring through Equifax, Experian and TransUnion. The Military Officers Association of America has urged anyone who suspects their information has been misused to file a report at the Federal Trade Commission's IdentityTheft.gov, warning that Social Security numbers exposed in the breach do not expire and can be used for fraud years after a notice letter arrives.

What remains unclear is almost as notable as what is known. The Pentagon has not said whether the breach was the work of a criminal group, a foreign intelligence service or an opportunistic insider, nor has it explained the roughly two-month gap between discovering the vulnerability in mid-July and beginning notifications in September. Lawmakers on the House and Senate Armed Services committees have not yet said whether they will seek a public accounting of the incident, though past breaches of military personnel data — including a 2015 hack of a similar scope — have prompted hearings and, eventually, new data-security mandates for defense contractors and agencies.

For now, the practical advice to the roughly 3 million people affected is the same offered after most large breaches: monitor credit reports, consider a credit freeze, and watch for phishing attempts that reference accurate personal details. For an agency that spends tens of billions of dollars a year on cybersecurity, the episode is a reminder that some of its oldest administrative systems — not its weapons networks — remain among its softest targets.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
Claire Fontaine · Technology & Regulation Correspondent

Reports on technology and its regulation for UBStandard, with a focus on Brussels, AI policy and Europe's digital economy.

[email protected]
Related coverage Front page →