Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Pentagon Personnel Agency Data Breach Impacts 3 Million People

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.

Pentagon DOD

The US Defense Manpower Data Center (DMDC), which maintains personnel records for the Pentagon, has started notifying people that their personal information was exposed. 

According to the DMDC’s notice, unauthorized users had access to one of its file-sharing servers for roughly nine months.

A copy of the notification letter, dated September 18 and shared online by a recipient, says the problem was discovered in mid-July.

“On July 16, 2026, a security vulnerability in a DMDC file sharing system was discovered, which allowed unauthorized users to access files. DMDC immediately updated the file sharing system to patch the vulnerability and the system was restored,” the letter reads.

The letter does not name the affected file-sharing product or describe the vulnerability.

“Analysis identified that between October 2025 and the date of discovery, a small number of unauthorized users accessed files on a server containing unencrypted PII,” the letter says.

Advertisement. Scroll to continue reading.

Exposed records varied by individual and included Social Security numbers alongside names, dates of birth, contact details, demographic data, and military occupational specialties.

“At this time, DoW does not have any indications of misuse of the accessed information,” DMDC says.

The letter does not say how many people are affected. A Department of War official told CNN that the breach impacts 2.76 million living individuals and 294,000 deceased individuals.

According to its website, DMDC held at least 60 million records as of fiscal year 2024. Those records cover military and civilian personnel, contractors, family members, retirees and veterans.

It is unclear who is behind the cyberattack. No known cybercrime group appears to have taken credit for an attack on the DMDC.

DMDC says it launched privacy and cybersecurity incident response actions after finding the vulnerability. 

Related: DC Health Agency Exposes 400,000 Beneficiary Records

Related: Astrana Health Data Breach Impacts Private, Confidential Information

Related: ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

David Cass has joined Grayscale Investments as Chief Risk Officer.

Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.

Alex Stamos has become Chief Information Security Officer at Cognition.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.