Pentagon Data Breach Exposed Records of More Than 3 Million People

A breach at the Defense Manpower Data Center (DMDC), the Pentagon unit that keeps personnel records for the US military, exposed personal information on more than 3 million people, according to reports from Federal News Network, Stars and Stripes and TechCrunch. The breach became widely known in late September 2026, after notification letters reached affected people.

What was exposed

According to Federal News Network, the affected group includes nearly 2.8 million living people and 294,000 deceased people with ties to the US military. Stars and Stripes put the number of living people at 2.76 million.

The exposed data included names, contact information, dates of birth, Social Security numbers, sex, race and military job information, according to Stars and Stripes. Federal News Network and TechCrunch both reported that the records were stored unencrypted.

How it happened

The reports say unauthorized users exploited a security vulnerability in a file-sharing system run by DMDC. Federal News Network reported that a small number of unauthorized users had access from October 2025 through July 2026, close to a year. The flaw was discovered and patched on July 16, 2026.

DMDC maintains records on more than 60 million people, including troops, veterans, current and former civilian employees, contractors and military family members, according to Federal News Network. TechCrunch noted that DMDC also manages credentials used for system access across the military.

How it came to light

Stars and Stripes reported that the notification letter sent to affected people was dated September 18, 2026, and that a copy was posted to a Reddit forum for Air Force members. Military Times first reported the breach on September 24, according to Stars and Stripes.

The letter says DMDC started privacy and cybersecurity incident response actions as soon as it found the flaw, in line with Office of Management and Budget and department guidelines.

The Pentagon's response

The Pentagon says it has no indication that anyone's personal information has been misused. TechCrunch noted that the department did not explain how it reached that conclusion and did not say whether the attackers had made contact. The identity of the people behind the breach is unknown.

Federal News Network reported that officials declined to say who accessed the data, whether specific groups were targeted, or why the information was not encrypted. Affected people are being offered 12 months of free credit monitoring through IDX, a data breach recovery services company.

Why it matters

Social Security numbers and service details cannot be changed the way a password can, so people whose records were exposed may face a long-term risk of identity fraud. TechCrunch compared the incident with the 2015 Office of Personnel Management breach, which compromised records of more than 22 million US government employees. The disclosure also comes in the same month as a separate claimed breach involving FBI personnel data.


Sources

This article was drafted with AI assistance and checked against the sources above. Company claims are reported as claims. Cover image is AI-generated.