Pentagon Data Breach Exposes Personal Information of More Than 3 Million People
The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of military personnel and others that hackers accessed its personnel management system and stole sensitive information.
According to a data breach notification letter shared online, unauthorized users exploited vulnerabilities in a DMDC file-sharing system between October 2025 and July 2026. The attackers accessed personally identifiable information (PII) belonging to affected individuals.
DMDC breach affected more than 3 million people
The exposed information varies by person and may include Social Security numbers (SSNs), names, dates of birth, contact information, gender, race, and military-related information.
The breach reportedly affected more than 3 million people, including approximately 2.8 million survivors and 294,000 individuals described as “dead,” according to Federal News Network.
“Upon discovering the security vulnerability, DMDC immediately initiated privacy and cybersecurity incident response actions in accordance with the guidelines and policies of the Office of Management and Budget and the Department,” the agency told affected individuals.
“We are evaluating and taking appropriate steps to strengthen the cybersecurity posture of the DMDC system,” DMDC added.
Free credit monitoring offered to affected individuals
The Department of Defense says it is offering 12 months of free credit monitoring through IDX, its data breach and recovery service provider. Affected individuals must register for the service by August 19, 2027.
A Department of Defense spokesperson did not immediately respond to BleepingComputer’s request for additional details about the breach.
DMDC maintains more than 60 million records
Founded in 1974, DMDC is an operational support center that houses more than 60 million records belonging to military personnel, civilians, contractors, families, retirees, and veterans. The records support Department of Defense benefits and entitlement authorization, training, financial services, and other programs.
DMDC also manages Department of Defense human resources programs and conducts research and analysis as directed by the Office of the Secretary of Defense.
“The services and access to data we provide support so many critical government agencies, including the Legislature, Human Services, Defense, Labor, Health, Finance, Veterans Affairs, Research, and more,” DMDC says.
FBI breach claims follow Pentagon incident
The incident follows another major data breach in which the extortion group ShinyHunters claimed to have used an Oracle PeopleSoft zero-day vulnerability to compromise the FBI’s FBIjobs.gov website.
ShinyHunters claimed it stole terabytes of data belonging to “nearly every FBI agent,” including employee records, names, Social Security numbers, home addresses, and assignments. A member of the FBI’s remote operations unit, which was involved in the hacking operation, was reportedly among those affected.
ShinyHunters told BleepingComputer that the FBI intrusion was not financially motivated and that the group did not intend to release the stolen data or blackmail the FBI.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



