Pentagon DMDC breach exposes data of over 3 million people
The Defense Manpower Data Center (DMDC), the agency that keeps personnel records for the US Pentagon, is notifying people that their personal information was exposed after attackers accessed one of its file-sharing servers.
According to the notice, unauthorized users could reach the server for about nine months before anyone noticed.
A vulnerability open since October 2025
A recipient posted a copy of the notification letter online. It is dated September 18 and says the agency found the problem in mid-July.
"On July 16, 2026, a security vulnerability in a DMDC file sharing system was discovered, which allowed unauthorized users to access files. DMDC immediately updated the file sharing system to patch the vulnerability and the system was restored," the letter states.
DMDC does not say which file-sharing product was affected, and it gives no technical details about the flaw.
The follow-up investigation found that the access began well before the discovery. "Analysis identified that between October 2025 and the date of discovery, a small number of unauthorized users accessed files on a server containing unencrypted PII," the letter says. PII stands for personally identifiable information.
What was exposed
The exposed data differs from person to person. It includes Social Security numbers along with names, dates of birth, contact details, demographic data and military occupational specialties, which are the job codes used to classify service members' roles.
The letter refers to the Department of War (DoW), the name now used for the US defense department. It says the department has seen no evidence so far that the stolen information has been misused.
"At this time, DoW does not have any indications of misuse of the accessed information," DMDC says.
Close to 3.1 million people affected
The letter does not give a victim count. A Department of War official told CNN that the incident affects 2.76 million living individuals and 294,000 deceased individuals.
That is only a small part of what the agency holds. DMDC's website says it had at least 60 million records as of fiscal year 2024. These cover military and civilian personnel, contractors, family members, retirees and veterans.
It is not clear who carried out the attack. No known cybercrime group appears to have claimed it.
DMDC says it started privacy and cybersecurity incident response actions after finding the vulnerability.
Our Take
The numbers matter here, but so does the timeline. Attackers had roughly nine months of access to a server holding unencrypted Social Security numbers. That points to two basic failures at once: a vulnerable file-sharing system that went unnoticed for a long time, and sensitive data stored without encryption. Either control alone could have limited the damage.
File-sharing and other internet-facing systems have been a common way in for many major breaches, and this incident appears to follow that pattern. Because DMDC has not named the product or the flaw, other organizations running similar software cannot yet tell whether they face the same risk. It is worth watching whether the agency or a vendor discloses more details, and whether a CVE is linked to the incident.
The data involved also raises concerns beyond ordinary identity theft. Records that combine personal identifiers with military occupational specialties could interest criminals running phone-based social engineering as well as intelligence services looking for people in sensitive roles. The lack of a public claim from any cybercrime group, together with the small number of intruders described, leaves the question of attribution open. Readers should be careful not to assume a nation-state link based only on who the victim is.
People who receive a notice should expect targeted phishing that uses their service details to seem convincing. They should also consider credit monitoring or a credit freeze, since Social Security numbers cannot easily be changed. The statement that there is no sign of misuse reflects what DMDC knows today, and that could change as more information comes out.
