Pentagon Data Breach Exposes 3 Million People’s Personal Info
Major Security Incident at Pentagon Exposes Data of Over 3 Million Individuals
The Defense Manpower Data Center (DMDC), a critical component of the U.S. Department of Defense, has confirmed a cybersecurity breach impacting personal information for more than 3 million individuals. The incident involves 2.76 million living individuals, encompassing active and former military personnel, their dependents, and 294,000 deceased individuals, as disclosed by a Department of Defense official to CNN.
The DMDC, established in 1974, manages centralized records for military personnel, including service status, benefits eligibility, and other administrative data. A security flaw in the agency’s file-sharing system was identified on July 16, 2026, enabling unauthorized access to files. Investigation revealed that between October 2025 and the discovery date, a limited number of individuals accessed a server containing unencrypted personally identifiable information (PII).
Exposed data varied per individual but included Social Security numbers linked with names, birth dates, contact details, racial demographics, gender, and military occupational specialties. The DMDC has not detected evidence of data misuse and has not disclosed the identities of those who accessed the files or whether the information was copied.
The agency stated it is implementing measures to strengthen cybersecurity protocols. Affected individuals are being offered 12 months of complimentary credit monitoring services through IDX, a third-party breach response firm contracted by the Department of Defense.
This incident marks the second significant breach affecting U.S. federal agencies within weeks, following reports of the ShinyHunters group claiming to have stolen personal data from FBI employees. The breach underscores ongoing challenges in securing sensitive government systems, with the DMDC’s compromised server highlighting vulnerabilities in data encryption and access controls.
Further details about the breach’s scope and mitigation efforts are expected as investigations continue.
