Breach report
Pentagon personnel data centre exposed data of about 3 million people through a vulnerable file-sharing server

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
The US Defense Manpower Data Center says unauthorised users reached a file-sharing server between October 2025 and July 2026. Unencrypted Social Security numbers and service details of 2.76 million living and 294,000 deceased people were exposed.
What happened
The US Defense Manpower Data Center (DMDC), which holds personnel records for the Department of Defense, has told affected people that a small number of unauthorised users accessed files on one of its file-sharing servers. According to the notification letter reported by Military Times and Stars and Stripes, the access took place at some point between October 2025 and 16 July 2026, when the vulnerability was found and patched. Letters were sent in September.
A defense official told ABC News, as reported by Stars and Stripes, that the unencrypted data of 2.76 million living people and 294,000 deceased people was exposed.
Confirmed vs. claimed
Confirmed by the notification letter and a defense official: the unauthorised access, the time window, the data types and the totals. No attacker has been named, no group has claimed it, and the letter says no misuse has been detected so far. Some reports cite a letter mentioning up to 4 million people; we use the official's figure.
Who is affected
Current and former US service members, civilian employees and some family members whose records DMDC held. The exposed files included Social Security numbers together with at least one other detail such as name, date of birth, contact details, sex, race or military job information.
What to do
- If you received a letter, enrol in the year of free credit monitoring it links to, through the Pentagon's own site.
- Consider a credit freeze with the three US credit bureaus.
- Expect phishing that mentions DoD, DMDC or your service record. Do not click links in unexpected messages; go to official sites directly.
Sources
More breaches in United States
- FBI (FBIJobs.gov portal) — 22 Sep 2026
- IDScan.net — 01 Sep 2026
- Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) — 27 Aug 2026
- Boston Scientific — 26 Aug 2026
- Aesto Health — 14 Aug 2026