Key facts
- Millions of current and former U.S. military personnel records were stolen in a data breach.
- The breach affected approximately 2.8 million living people and nearly 300,000 deceased individuals.
- Personally identifiable information, including Social Security numbers, was stolen from unencrypted records.
- The data breach occurred over several months between October 2025 and mid-July 2026.
- The Defense Manpower Data Center (DMDC) is responsible for maintaining these records.
The U.S. government has notified millions of current and former military personnel and staff about a significant data breach impacting the Pentagon’s personnel records. The breach, which occurred over several months between October 2025 and mid-July 2026, involved unauthorized users exploiting a security vulnerability in an unspecified file-sharing system.
According to a notification from the Defense Manpower Data Center (DMDC), the stolen information includes personally identifiable details such as Social Security numbers, names, dates of birth, sex, race, and other military service information. These records were reportedly unencrypted.
A Pentagon official stated that the breach affects approximately 2.8 million living individuals and close to 300,000 deceased individuals. The DMDC, a unit within the Department of Defense, manages over 60 million records for military and civilian staff and their families, playing a crucial role in identity management for accessing Pentagon systems and facilities.
While the Department of Defense has indicated no indication of misuse of the stolen data, the method for reaching this conclusion was not provided. The identities of the hackers are currently unknown. This incident follows a recent data breach at the FBI, attributed to the ShinyHunters hacking group, which exposed personal information of agents and staff. Such breaches raise concerns about potential profiling, targeting, or coercion of federal workers by foreign governments.
