NG Solution Team
Cybersecurity

Pentagon Data Breach Exposes Records of Over 3 Million Personnel

A cybersecurity breach at the Pentagon’s Defense Manpower Data Center exposed sensitive personal information for more than three million people, including serving and former military personnel, civilian employees and others connected to the U.S. military. A U.S. defense official said about 2.76 million living people and roughly 294,000 deceased individuals were affected.

The compromised data included Social Security numbers, dates of birth, contact information and details about jobs performed by military and civilian personnel. The exposed information also contained military occupational specialties. National security experts expressed concern that such details could enable hostile intelligence organizations to identify personnel performing sensitive duties and raise risks of identity theft.

Pentagon systems and scope of exposure

The affected system belongs to the Defense Manpower Data Center (DMDC), which maintains more than 60 million personnel records covering active-duty troops, reservists, civilian employees, contractors, retirees, veterans and military family members. A notification letter dated September 18 reviewed by a publication indicated the compromised records were not encrypted, potentially increasing the risks associated with the exposure.

Discovery, response and assistance offered

Unauthorized access to the DMDC system reportedly began in October 2025 and continued for approximately nine months before the vulnerability was discovered and addressed in July 2026. The vulnerability was identified on July 16 in a file-sharing system. A U.S. defense official confirmed a small number of unauthorized users had accessed personally identifiable information between October 2025 and July 2026 and said the agency immediately addressed the security vulnerability after discovery.

Defense officials have said there is currently no evidence that the exposed information has been misused. The Pentagon has begun notifying affected individuals and is offering identity protection, credit monitoring and identity-restoration services. Affected individuals are being offered one year of credit monitoring and identity-restoration assistance through IDX, a private company contracted by the Department of Defense. The identity of those responsible for the breach remains unknown.

Related FBI personnel investigation

Separately, the FBI is investigating a potential compromise of its recruitment website, FBIJobs.gov, after a threat actor claimed to possess sensitive personal information belonging to bureau personnel. The potentially compromised information reportedly included employees’ names, home addresses, telephone numbers, Social Security numbers, dates of birth and emergency contact details. The FBI has been operating on the assumption that all its employees’ personal information may have been compromised. No connection has been established between the FBI incident and the Pentagon database breach.

Related posts

Trezor Users Targeted via Compromised Email Service

David Jones

Chrome fixes actively exploited V8 zero-day (CVE-2026-85046)

Jessica Williams

Nigerian Army Detects Cyber Breach Attempt on X Account

Jessica Williams

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy