Pentagon Data Breach: 3 Million Records Stolen by Hackers
A significant data breach has compromised the personal information of over three million individuals associated with the U.S. Department of Defense.
Overview of the Breach
A significant data breach has compromised the personal information of over three million individuals associated with the U.S. Department of Defense. The Defense Manpower Data Center (DMDC), which manages human resources for military personnel, confirmed that unauthorized access occurred between October 2025 and July 2026 due to a vulnerability in its file-sharing infrastructure.
Details of the Breach
Timeline and Vulnerability
The breach occurred between October 2025 and July 2026 due to a vulnerability in the DMDC’s file-sharing infrastructure.
Impact on Affected Individuals
Affected individuals received notifications detailing the exposure of sensitive data, including Social Security numbers, names, dates of birth, contact details, gender, ethnicity, and military-specific records. The breach impacted 2.8 million living individuals and 294,000 deceased persons, according to Pentagon officials.
Response and Mitigation
The DMDC stated it initiated immediate cybersecurity protocols upon discovering the flaw, aligning with federal guidelines to address the incident. The agency emphasized ongoing efforts to strengthen system security and prevent future compromises. Affected parties are eligible for 12 months of complimentary credit monitoring through IDX, with enrollment required by August 19, 2027.
Background on the DMDC
The DMDC, established in 1974, maintains records for over 60 million individuals, including active-duty personnel, retirees, contractors, and family members. These databases support critical functions such as benefits administration, financial processing, and personnel management for the DoD.
Related Cybersecurity Incident
This incident follows a separate breach attributed to the ShinyHunters cybercriminal group, which exploited a zero-day vulnerability in Oracle PeopleSoft to access FBIjobs.gov. The gang claimed to have obtained terabytes of data, including details of nearly all FBI agents, though they stated no financial motives and no intent to leak the information.
Implications and Recommendations
The breach highlights vulnerabilities in government file-sharing systems and underscores the risks of unpatched software. Affected individuals are advised to monitor their accounts and utilize the provided mitigation services. No further details about the Pentagon breach’s technical specifics or threat actor identification were disclosed at the time of reporting.
