IT-PUB NEWS

Pentagon breach exposed millions of military records

02.10.2026 12:03 • Author: IT-PUB

Pentagon breach exposed millions of military records

Attackers exploited a file-sharing flaw for months, accessing unencrypted Pentagon personnel data including Social Security numbers and service details.

The U.S. government is warning millions of current and former military personnel that their personal data was stolen in a months-long breach of Pentagon records. The case stands out not just for its scale, but for the sensitivity of the files involved, including Social Security numbers and other personal identifiers.

The breach comes amid a run of thefts involving federal workers’ data. It also puts fresh attention on how the Defense Department stores and protects records used for benefits, identity checks, and access to military systems and facilities.

Attackers exploited a file-sharing weakness for months

According to a data breach notification from the Defense Manpower Data Center, or DMDC, unauthorized users exploited a security vulnerability in an unspecified file-sharing system over several months. The activity is said to have taken place between October 2025 and mid-July 2026.

The notice, shared on Reddit, says the attackers accessed personnel records that were not encrypted. As IT-PUB News notes, that matters because the files contained personal information that could identify individuals and potentially be used for fraud or impersonation.

The exposed data included names, dates of birth, sex, race, Social Security numbers, and other information related to military service.

About 3.1 million people are in the affected group

According to CNN and Federal News Network, a Pentagon official said the breach affects about 2.8 million living people, as well as close to 300,000 deceased individuals.

The U.S. military has 1.3 million active service members as of March, which shows the affected group extends well beyond currently serving troops. The breach also appears to include former service members and other people whose records are held by the Defense Department.

Susan Gough, a spokesperson for the Department of Defense, confirmed the number of people affected in an emailed statement. She did not answer TechCrunch’s questions about the incident, including whether officials had received any communication from the hackers, whose identities remain unknown.

DMDC handles benefits records and military identity systems

The DMDC may not be widely known outside government and military circles, but it plays a central role in the Defense Department’s records system. It maintains more than 60 million records for military and civilian staff and their family members, helping determine benefits and entitlements such as healthcare and retirement.

It also serves as the military’s “leading identity management provider,” linking active service members, employees, and contractors to credentials such as smart cards and passwords. Those credentials are used to access Pentagon computer systems, buildings, and bases.

That makes this more than a routine records leak. When an organization responsible for identity management is compromised, the concern is not limited to exposed personal details. It also touches access, verification, and trust in internal systems.

The Pentagon says it has no sign of misuse

The Department of Defense said it does not have any indication that the information was misused, though it did not explain how it reached that conclusion.

That leaves a major uncertainty. The exposed records were sensitive, the breach lasted for months, and the full scope of any downstream risk has not been described publicly. Even without confirmed misuse, theft of this kind of data can create long-term concerns for people whose details were included.

The case also points to a familiar problem in large government systems: data collected for administrative purposes can become highly valuable to attackers if it is not properly protected.

The breach follows other thefts of federal personnel data

The Pentagon breach is the latest in a series of incidents involving federal personnel data. Earlier in September, TechCrunch reported a breach at the FBI attributed to the ShinyHunters hacking group.

In that case, the hackers told TechCrunch they had taken personal information from most of the FBI’s agents and staffers, including applicants. The breach was described as a “counterintelligence disaster” because such information could be used to profile, target, or coerce federal workers into giving up sensitive information.

The ShinyHunters hackers also said they would not publicly release the stolen FBI data.

The DMDC incident resembles that breach in one important way: both involve records that could reveal more than names and contact details. They include information tied to employment, service history, and identity, which can raise the risks if the data falls into the wrong hands.

The incident recalls earlier government personnel breaches

The Pentagon breach also echoes past government data thefts. In 2015, hackers broadly attributed to China breached the U.S. government’s human resources department, the Office of Personnel Management, and stole the private records of more than 22 million U.S. government employees, many of whom held security clearances.

That case remains one of the clearest examples of how damaging a large-scale personnel breach can be. The new DMDC incident is smaller than the OPM theft, but it raises similar concerns around identity data, government records, and the potential for long-term harm to the people affected.

For current and former military personnel, the practical impact may emerge slowly. The immediate issue is whether the stolen information will be used, shared, or sold. The broader concern is whether the systems that store and manage sensitive government identities are being protected well enough to prevent another breach of this kind.

The Department of Defense has said it has no indication of misuse so far. Still, with millions of records exposed and the attackers still unidentified, the incident is likely to stay under close scrutiny.


Improve SEO for a small/medium business website for $50