Breach tracker

Breach report

Pentagon personnel data centre exposed data of about 3 million people through a vulnerable file-sharing server

ConfirmedDisclosed Report published United StatesGovernmentBy Vivek Kumar
Records 3.05MCause Vulnerability
Editorial illustration of a server rack beside an open file-sharing folder with exposed file cards, with the headline Pentagon Data Exposure.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

The US Defense Manpower Data Center says unauthorised users reached a file-sharing server between October 2025 and July 2026. Unencrypted Social Security numbers and service details of 2.76 million living and 294,000 deceased people were exposed.

What happened

The US Defense Manpower Data Center (DMDC), which holds personnel records for the Department of Defense, has told affected people that a small number of unauthorised users accessed files on one of its file-sharing servers. According to the notification letter reported by Military Times and Stars and Stripes, the access took place at some point between October 2025 and 16 July 2026, when the vulnerability was found and patched. Letters were sent in September.

A defense official told ABC News, as reported by Stars and Stripes, that the unencrypted data of 2.76 million living people and 294,000 deceased people was exposed.

Confirmed vs. claimed

Confirmed by the notification letter and a defense official: the unauthorised access, the time window, the data types and the totals. No attacker has been named, no group has claimed it, and the letter says no misuse has been detected so far. Some reports cite a letter mentioning up to 4 million people; we use the official's figure.

Who is affected

Current and former US service members, civilian employees and some family members whose records DMDC held. The exposed files included Social Security numbers together with at least one other detail such as name, date of birth, contact details, sex, race or military job information.

What to do

  • If you received a letter, enrol in the year of free credit monitoring it links to, through the Pentagon's own site.
  • Consider a credit freeze with the three US credit bureaus.
  • Expect phishing that mentions DoD, DMDC or your service record. Do not click links in unexpected messages; go to official sites directly.

Sources

More breaches in United States