Pentagon Data Breach Exposes Social Security Numbers and Military Personnel Data

A Pentagon personnel data breach exposed unencrypted Social Security numbers and military information after unauthorized users accessed a vulnerable DMDC server for months.
Aerial view of the Pentagon in Washington, D.C., with the Pentagon emblem centered over the building.

A data breach involving the U.S. Department of Defense’s Defense Manpower Data Center exposed unencrypted Social Security numbers and other sensitive information belonging to military personnel after unauthorized users gained access to files through a vulnerable file-sharing system.

The Defense Manpower Data Center, known as DMDC, discovered the security vulnerability on July 16, 2026. An investigation subsequently determined that unauthorized users had accessed files on the affected server between October 2025 and July 16, meaning the exposure potentially persisted for approximately 9 months before discovery.

The Department of Defense began notifying affected individuals in September. The exact number of people affected has not been publicly confirmed, although 2 sources familiar with the incident reportedly said approximately 4 million Defense Department personnel may be impacted.

Social Security numbers stored unencrypted

According to breach notifications sent to affected individuals, the compromised server contained files holding unencrypted personally identifiable information.

The exposed information included Social Security numbers along with at least 1 additional identifying data element. Depending on the affected individual, that information could include names, dates of birth, contact information, sex, race and military personnel information such as occupational specialty.

The specific information exposed therefore varies between victims.

DMDC has not publicly disclosed whether the approximately 4 million figure accurately represents the final number of affected people, and it remains unclear whether every potentially exposed record contained a Social Security number.

The agency said it currently has no indication that the compromised information has been misused.

Unauthorized access began in October 2025

The incident originated from a security vulnerability affecting a DMDC file-sharing system.

Unauthorized users were able to access files stored on the vulnerable server beginning in October 2025, according to the breach notification. The activity continued until DMDC discovered the vulnerability on July 16, 2026.

After discovering the issue, DMDC updated the file-sharing system to address the vulnerability and restored the system.

Public information about the technical cause remains limited. The Defense Department has not identified the affected file-sharing product, disclosed a vulnerability identifier or explained whether the unauthorized users exploited a previously known security flaw.

No threat actor has been publicly identified in connection with the breach.

DMDC maintains extensive Defense Department personnel records

The Defense Manpower Data Center plays a central role in maintaining and verifying information associated with people connected to the Department of Defense.

DMDC systems support identification, authentication, personnel management and benefits-related functions involving military personnel, civilian employees, contractors, retirees, veterans and family members.

The organization maintains tens of millions of Defense Department records, making the exposure of a server containing personnel information particularly sensitive.

Military occupational information combined with Social Security numbers and other identifying details could create risks extending beyond conventional identity theft. Depending on the individuals and information involved, exposed personnel data could also support highly targeted phishing, impersonation and social-engineering campaigns.

Broader investigation underway

The Defense Department is reportedly conducting a broader examination of its systems following discovery of the breach to identify additional vulnerabilities or unauthorized access.

Several important details remain unknown, including who accessed the server, the total number of affected individuals, the full volume of information accessed and why the unauthorized activity remained undetected for months.

Breach follows separate FBIjobs.gov cyberattack

The DMDC disclosure comes days after another significant federal cybersecurity incident emerged involving the FBI’s recruitment infrastructure.

On Sept. 24, BreachNews reported that the FBI is investigating unauthorized activity affecting FBIjobs.gov after ShinyHunters claimed it compromised the recruitment system and obtained sensitive information involving FBI personnel and job applicants.

ShinyHunters claims it exploited a previously unknown Oracle PeopleSoft vulnerability and stole between 2 TB and 3 TB of data. The group has made additional claims involving access to other FBI-controlled infrastructure, but the alleged PeopleSoft zero-day, volume of stolen information and broader extent of the intrusion have not been independently confirmed.

The FBI confirmed that it is aware of claims regarding unauthorized activity affecting FBIjobs.gov and said the incident is under investigation.

The 2 incidents are separate. There is currently no evidence connecting the FBIjobs.gov attack to the Defense Manpower Data Center breach, and the Defense Department has not attributed the DMDC compromise to ShinyHunters or any other threat actor.

Together, the incidents place renewed attention on the security of federal systems holding sensitive personnel information. Both involve systems associated with government employees or applicants, although the confirmed circumstances and technical details differ substantially.

DMDC is offering affected individuals 1 year of credit monitoring and identity restoration services.

The breach notification states that there is currently no indication the exposed information has been misused. However, Social Security numbers and other permanent identifying information can retain value for identity fraud and targeted social engineering long after the initial compromise.

The Department of Defense has not publicly attributed the incident to a criminal or nation-state threat actor.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →