Pentagon Data Breach Exposes Sensitive Information on More Than 3 Million People
A security breach involving a Pentagon personnel information system exposed sensitive personal information belonging to more than 3 million people, including current and former members of the U.S. military, civilian employees and others connected to the Defense Department. A U.S. defense official said unauthorized users were able to access the information for several months before the vulnerability was discovered and addressed.
The affected system is operated by the Defense Manpower Data Center, or DMDC, one of the Pentagon's main repositories for personnel information. According to the defense official, the breach affected approximately 2.76 million living people and another 294,000 deceased individuals. The exposed information included names, Social Security numbers, dates of birth, contact information and details about people's military jobs, although the exact information varied from person to person.
The unauthorized access reportedly began in October 2025 and continued until July 2026. The DMDC discovered the security vulnerability on July 16 and moved to patch the affected system. A breach notification reviewed by Military Times said unauthorized users had accessed files containing unencrypted personally identifiable information stored on a file-sharing system.
The incident was not immediately detected, meaning the unauthorized access continued for roughly nine months before the vulnerability was identified. Defense officials have not publicly disclosed who accessed the information, how the attackers obtained access or whether the breach was deliberately carried out by a particular hacking group. Officials have also declined to provide several additional details about the incident while the investigation continues.
The DMDC maintains more than 60 million personnel records covering a broad range of people connected to the Defense Department, including active-duty and reserve service members, civilian employees, contractors, retirees, veterans and military family members. The agency also plays a major role in identity verification and access management for Defense Department personnel.
Despite the scale of the exposure, the Pentagon said it has found no evidence so far that the information has been misused. The Defense Department is offering affected individuals one year of credit monitoring and identity-restoration services through IDX, according to breach notifications sent to people whose information was involved.
The breach comes amid a series of recent incidents involving sensitive U.S. government personnel information. The FBI has also been investigating a separate compromise of its jobs website, in which personal information connected to FBI employees and applicants was allegedly obtained. The two incidents have renewed attention on the security of government systems that hold large amounts of personal information.
For the Pentagon, the incident highlights the potential consequences of vulnerabilities in systems containing large volumes of personnel data. While officials have not reported evidence that the exposed information has been misused, the combination of Social Security numbers and employment or military information could create risks for affected individuals. The Defense Department continues to investigate the breach and assess the security of the affected system.




