Pentagon notifies 2.76 million people of monthslong personnel data breach

· CyberSecurity

TLDR

  • The Pentagon is notifying 2.76 million living current and former Department of Defense-affiliated people, plus 294,000 deceased ones, that a monthslong breach exposed their personal data.
  • Attackers exploited a flaw in a Defense Manpower Data Center (DMDC) file-sharing system to access unencrypted records between October 2025 and July 2026.
  • Stolen data includes Social Security numbers, full names, dates of birth, addresses, sex, race and military occupational specialty, detail an adversary could use to identify high-value personnel.
  • It is the second breach of sensitive US government personnel data to surface in recent months, after ShinyHunters' claimed hack of the FBI's recruitment site.

The Defense Manpower Data Center, the Pentagon unit that maintains more than 60 million personnel records for military, civilian and contractor staff, discovered on 16 July 2026 that a vulnerability in one of its file-sharing systems had let unauthorised users access files, and patched it immediately.1 A subsequent investigation found that someone had been exploiting the flaw since October 2025, extracting unencrypted data including Social Security numbers, names, dates of birth, contact details, sex, race and occupational specialty.1 A Department of War official told ABC News the breach affects 2.76 million living individuals and 294,000 deceased ones.3

Investigators have not disclosed which file-sharing system was targeted or the nature of the flaw.1 Cybersecurity firm Black Duck's Collin Hogue-Spears said the combination of personal identifiers and occupational data is what makes the haul dangerous: "A Social Security number identifies a person. An occupational specialty tells an adversary why that person matters."3 He added that the records were reachable through the file-sharing system for roughly nine months regardless of any encryption at rest, since that protection does not stop someone reading files through the system that decrypts them.3 Officials say there is currently no evidence the data has been misused.1

The breach is the second in as many months to expose sensitive US government personnel information. In September, the extortion group ShinyHunters claimed to have hacked the FBI's recruitment site and stolen records of thousands of current and former employees, some with job titles tied to investigating China or Russia, before saying this week it would not release the data after a Dutch arrest of an alleged member.2 Taken together, security researchers say the two incidents represent one of the largest potential espionage hauls of US government personnel data since the 2015 Office of Personnel Management breach, in which Chinese state hackers obtained more than 22 million records.2

Why it matters: Social Security numbers paired with military occupational specialty give a foreign intelligence service a searchable roster of who matters and why, turning a routine file-sharing vulnerability into a nine-month espionage opportunity against the people who maintain America's defense workforce.

Sources

  1. Massive Pentagon hack sees records of 2.7 million US military personnel leaked during months-long data breach (TechRadar)
  2. Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data (Ars Technica)
  3. Pentagon breach exposes military and civilian personnel records (Computing)