The news
A Pentagon data breach at the Defense Manpower Data Center (DMDC), which keeps the Defense Department's personnel records, let unauthorized users open files on more than 3 million people from October 2025 until July 16, 2026, according to a notification letter and defense officials.
The letter, dated September 18 and first reported by Military Times on September 24, says a security vulnerability in a DMDC file-sharing system was discovered on July 16 and that it allowed unauthorized users to access files holding unencrypted personal information. Military Times reported that two defense officials confirmed the letter was authentic.
The exposed data included Social Security numbers, names, dates of birth, contact information, sex, race and military occupational specialty, according to Military Times and Stars and Stripes. Federal News Network reported that the types of data varied from person to person. DMDC said in the letter that it patched the file-sharing system immediately after the discovery.
The letter does not give a count. A defense official told CNN that 2.76 million living people and 294,000 deceased people were affected, SecurityWeek reported; Stars and Stripes cited the same figures from ABC News. An earlier Military Times report had cited two sources estimating about 4 million people were potentially affected.
DMDC holds more than 60 million records covering military and civilian personnel, contractors, family members, retirees and veterans, according to SecurityWeek and Stars and Stripes. A Pentagon official told Federal News Network that a "small number of unauthorized users" had access to the data, but declined to say who they were, whether they targeted particular groups or why the data was not encrypted.
The letter says the department has no indication the information has been misused. It is offering one year of credit monitoring and identity-restoration services through the contractor IDX, Military Times and Federal News Network reported. SecurityWeek reported that no known cybercrime group has claimed responsibility.
The numbers
- Living people affected (defense official, via CNN and ABC News)
- 2.76 million
- Deceased people affected (same official)
- 294,000
- Unauthorized access window
- October 2025 to July 16, 2026
- Records held by DMDC (SecurityWeek, Stars and Stripes)
- More than 60 million
- Free credit monitoring offered (via IDX)
- 1 year
Why CEOs should care
Defense contractors and other employers with military, veteran or reservist staff should assume some employees are in this data. Accurate names, birth dates, contact details and military job codes are the raw material for convincing phishing and impersonation. Tell staff to enroll in the IDX offer if they receive a letter, consider a credit freeze, and verify any unexpected request about benefits, clearances or payroll through a known phone number rather than the one in the message. The 294,000 deceased people in the count matter too: their identities can still be used for fraud, so families and executors should watch for new accounts or tax filings in their names.
CISOs should check the controls this incident exposed. Help desks that reset passwords after a caller gives a Social Security number and date of birth are relying on facts that may now be in unknown hands. Move resets to stronger verification, such as manager approval or a video check against an ID badge. Then audit your own file-sharing and file-transfer systems: is sensitive data encrypted at rest, is access logged, and would anyone notice an outsider reading files for nine months?
Boards and general counsel should use the timeline as a benchmark. DMDC found the flaw on July 16 and dated its letters September 18, about two months later. Ask management how long your own detection, investigation and notification would take, and whether contracts with government customers impose their own reporting clocks.
The bigger picture
Personnel data is valuable because it does not expire: a Social Security number and date of birth stay useful for fraud and targeting for decades. The Pentagon has not said who accessed the files or whether particular people were singled out, and Stars and Stripes noted the breach raises national security concerns because of how sensitive the data is. Until those questions are answered, affected people and their employers should treat the risk as ongoing.
What’s next
Watch for the Pentagon to name the file-sharing software and say who accessed it, for any change to the 2.76 million figure, and for reports of phishing or fraud that uses the exposed details. Lawmakers may also press the department on why the files were stored without encryption.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





