Pentagon Personnel Database Breach Exposes Sensitive Data of Millions
The U.S. Department of Defense has confirmed a major data breach involving the Defense Manpower Data Center (DMDC), one of its main repositories for personnel information.
The incident exposed sensitive information belonging to more than three million people, according to reports.
Approximately 2.76 million living individuals were reportedly affected, along with another 294,000 deceased individuals.
Unauthorized users were able to access files between October 2025 and July 16, 2026, meaning the exposure continued for approximately nine months before the problem was discovered and addressed.
The compromised files were reportedly stored without encryption and contained highly sensitive personal information.
The exposed data included:
- Social Security numbers
- Names
- Dates of birth
- Contact information
- Military personnel information
- In some cases, details about individuals’ military jobs
The Pentagon has said that it has not found evidence that the exposed information has been misused so far. The department is also offering affected individuals 12 months of identity protection and credit monitoring.
However, the absence of confirmed misuse does not necessarily mean the information has not been exploited.
The attackers reportedly had access to the information for months before the vulnerability in the file-sharing system was discovered and patched.
The scale of the incident is significant, although the DMDC database contains considerably more information. The center reportedly holds more than 60 million records covering military personnel, civilian employees, contractors, retirees, veterans and military families.
The combination of names, dates of birth and Social Security numbers creates a serious risk of identity theft and financial fraud.
The exposure of military job information introduces an additional security concern.
Knowing the roles and responsibilities of individual military personnel can help attackers create highly convincing spear-phishing and social-engineering attacks. Such information could also be valuable to foreign intelligence services seeking to identify or target particular members of the U.S. military.
The Pentagon has experienced other significant security incidents in the past. In 2008, a malware-infected USB device led to a major Department of Defense network intrusion that reportedly required an extended cleanup operation.
The 2015 breach of the U.S. Office of Personnel Management was even larger, exposing records connected to approximately 21.5 million people, including sensitive security-clearance information.
The latest DMDC incident therefore highlights the continuing risks faced by government organizations that maintain enormous databases containing sensitive personnel information.
Although the Pentagon says there is currently no evidence of misuse, the lengthy period of unauthorized access means affected individuals may need to remain alert for identity theft, targeted phishing attempts and other forms of fraud.
Leave a comment