One of the largest data breaches ever linked to the US Department of Defense and the Pentagon is causing concern. Millions of military personnel, veterans and others on the Pentagon are being told that their personal data was exposed to unauthorized users. The incident involves the Defense Manpower Data Center (DMDC), a critical organization that manages a huge amount of information about the US Department of Defense's manpower.
Over 3 million people are affected
According to updates sent by DMDC to affected individuals, the breach is linked to systems file sharing . The attackers appear to have gained unauthorized access to data between October 2025 and July 2026.
The DMDC says a limited number of unauthorized users were able to access sensitive information, which varies by individual. The data that may have been exposed includes names, Social Security numbers (SSNs), dates of birth, contact information, gender, racial characteristics, and information about military personnel.
Pentagon officials told the Federal News Network that the total number of people affected exceeds 3 million. Of those, about 2.8 million are living, while about 294,000 are deceased.
See also: National Archives of Canada: Failed hacking attempts by AI agents
Why is the leak considered particularly serious?
The nature of the data makes the incident significant not only from a privacy perspective, but also from a future cyberattack perspective. A combination of name, date of birth, SSN, and contact information can be used for identity theft, fraud, targeted phishing attacks, and social engineering.
Of particular concern is the fact that the data concerns people associated with the US defense. Even when the information does not directly contain classified military material, it can be used to create detailed profiles of specific individuals.
For example, a scammer who possesses a military member's personal information can craft much more convincing emails or phone calls, presenting the communication as a supposedly official update from a military service, insurance carrier, or government agency.

DMDC launched an investigation and took remedial measures
The Pentagon says that cybersecurity and privacy incident response procedures were activated once the vulnerability was identified. At the same time, DMDC says it is evaluating and strengthening the security of its infrastructure.
However, the fact that unauthorized access spans such a long period of time highlights one of the biggest challenges in protecting government systems: early detection of breaches.
A vulnerability can remain unknown for a long time, while attackers have the ability to gradually examine the available data and select those they consider most useful.
See also: ChatGPT trap: Fake GPT leads to ClickFix and RAT installation
Pentagon – Free protection for those affected
To mitigate the impact, the Pentagon is offering those affected free credit monitoring services through IDXfor 12 months.
Beneficiaries must register for the service by August 19, 2027.Credit monitoring can help identify suspicious activity, but it does not eliminate the risk posed by the exposure of personal data.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
An organization with a huge amount of information
DMDC was founded in 1974 and serves as a key operational support hub for the U.S. Department of Defense. Its systems include records for more than 60 million individuals, including military and civilian employees, contractors, family members, retirees, and veterans.
The information is used for benefits, entitlements, training, financial processes, and other programs related to DoD human resources. This explains why a breach in this ecosystem can have implications far beyond a single organization.

The ShinyHunters case and the FBI
The new revelation comes at a time when US government infrastructure has been the target of large-scale attacks, following an incident by ShinyHunters, who claimed to have compromised the FBIjobs.gov by exploiting a zero-day vulnerability in Oracle PeopleSoft.
The group claimed to have obtained several terabytes of data, including names, SSNs, home addresses, and personnel mission information. These claims should not be confused with independently verified figures for the total amount of data exposed.
ShinyHunters also stated that this particular attack was not financially motivated and that they did not plan to release the data or blackmail the FBI.
See also: Tax data theft in France using stolen passwords
New warning about government data security
The DMDC case highlights a broader problem: government agencies manage vast databases, which are particularly attractive targets for cybercriminals. Even when classified files are not stolen, the leak of millions of people's personal information can create long-term risks.
For affected individuals, the priority is to utilize available protection services, monitor financial accounts, and be extra vigilant against messages or phone calls that use personal information to appear trustworthy.
For government infrastructure, the incident is a reminder that data protection is not limited to responding to an attack. It requires continuous vulnerability scanning, access restriction, effective event logging , and rapid detection of unusual activity.
source: www.bleepingcomputer.com
