The Pentagon has begun notifying millions of current and former U.S. service members, civilian defense employees and their family members that hackers accessed their Social Security numbers, names and other personal records in a breach that went undetected for roughly nine months. A Defense Department official told Fox News that 2.76 million living people and 294,000 deceased individuals had records exposed, putting the confirmed total above 3 million.
The intrusion targeted the Defense Manpower Data Center, the Pentagon's central personnel-records repository, which verifies eligibility for pay, medical care, ID credentials and benefits for active-duty troops, reservists, veterans, retirees, contractors and relatives connected to the armed forces. According to reporting from TechCrunch, unauthorized users exploited a flaw in a file-sharing system tied to the center and had standing access from October 2025 until the Pentagon discovered the vulnerability on July 16.
Unencrypted and unnoticed for months
The records sitting in the compromised system were not encrypted, officials confirmed, which turned what might have been a contained intrusion into a full identity-theft exposure for millions of households. The stolen data includes Social Security numbers, full names, dates of birth, sex, race, contact information and military or civilian job details. Medical records, financial-account numbers and security-clearance background files do not appear to have been part of the exposure, based on current reporting.
After discovering and patching the flaw in July, the Department of Defense spent roughly two months assessing the scope of the intrusion before it began mailing breach-notification letters on September 18. No hacking group, nation-state or individual has been publicly named as responsible; officials have described the activity only as coming from "a small number of unauthorized users" who held access to the system for close to a year before anyone noticed.
The near-300,000 deceased individuals caught up in the breach point to how far back the exposed records reach, spanning decades of personnel history rather than recent enlistees. For surviving relatives, a dead person's Social Security number remains usable for fraud, extending the exposure beyond those who can monitor their own credit.
A smaller echo of 2015
The breach invites comparison to the 2015 Office of Personnel Management breach, which exposed roughly 22 million records, including fingerprints and full background-investigation files, and was publicly attributed to Chinese state-linked hackers. The DMDC incident is smaller and, so far, does not appear to include fingerprints or clearance narratives, but it shares the same root failure: sensitive federal personnel data sitting unencrypted inside a system that went unmonitored long enough for an intrusion to run for the better part of a year.
The Pentagon has said it currently has no indication the exposed information has been misused, though that assessment typically gets revised as more victims report fraud in the months after a breach of this size. The department has not named a responsible party, published a technical root-cause analysis, or confirmed whether a criminal or congressional inquiry has formally opened. No class-action lawsuit tied to the breach had been filed as of this week, though litigation in federal breach cases typically follows notification by weeks or months.
Defense personnel databases make persistent targets precisely because they centralize records on tens of millions of people — the DMDC system alone maintains data tied to more than 60 million individuals — in systems built up over decades and patched incrementally rather than redesigned. Military records are also valuable to foreign intelligence services even without classified material, since they can reveal unit assignments and career trajectories.
Affected individuals are being directed toward standard federal breach-response steps: placing a credit freeze with the three major credit bureaus, reviewing recent credit activity, enrolling in any credit-monitoring offer included with their notification letter, and filing a report with the FBI's Internet Crime Complaint Center if they suspect their data has already been used. Lawmakers are expected to press for a hearing or inspector-general review given the nine-month gap between intrusion and detection — a timeline that compares unfavorably with reforms federal agencies adopted after 2015.