Pentagon Data Breach Exposes 3 Million People — and Military Job Details

A Pentagon data breach exposed unencrypted PII tied to more than 3 million people after months of unauthorized access to a DMDC file-sharing system.

Sep 30, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A Pentagon data breach exposed sensitive personal information tied to more than 3 million people, including Social Security numbers and military job details, according to Defense Department officials.

The Defense Manpower Data Center breach affected 2.76 million living people and 294,000 deceased people. Exposed records varied by individual and also included names, dates of birth, contact information and demographic data.

ABC News reported that the job information could raise national security concerns because the records included details about work performed by military and civilian personnel.

How the DMDC breach exposed personnel data

A vulnerability in a DMDC file-sharing system allowed a small number of unauthorized users to access files containing unencrypted personally identifiable information, or PII. DMDC discovered the flaw on July 16, 2026, patched the system and restored service, according to a Sept. 18 breach notification reviewed by Military Times.

Analysis after the discovery found that unauthorized users had accessed files between October 2025 and July 16, 2026. The notice does not say the access was continuous or explain how the vulnerability was detected.

A Pentagon official told Federal News Network that the information exposed differed by person. Officials have not released a breakdown showing how many affected people were active-duty personnel, veterans, civilian employees, contractors or military family members.

The breached population represents only part of DMDC's holdings. The agency says it maintains more than 60 million DoD person records covering military and civilian personnel, contractors, family members, retirees and veterans.

Several technical details remain undisclosed. The breach notice does not identify the affected file-sharing product or describe the underlying vulnerability, while the Pentagon has not publicly identified the unauthorized users.

A separate September government network breach in Japan potentially exposed personal information tied to about 246,000 government and private-sector workers after an attacker exploited vulnerable external network equipment.

Advertisement

Unencrypted PII raises longer-term risk

The Pentagon says it has no indication that the accessed information has been misused. Affected individuals are being offered 12 months of credit monitoring and identity-restoration services through IDX.

The Federal Trade Commission says consumers can place free credit freezes and fraud alerts. Active-duty service members can also place an active-duty fraud alert, while active-duty and National Guard members are eligible for free electronic credit monitoring.

Encryption remains a central issue. IBM's 2026 breach research found that 53% of breached organizations lacked encryption for sensitive data at rest or in transit, while customer PII was the most commonly compromised data type, according to an analysis of IBM's breach findings.

Exposed personal details can also make phishing more convincing. SafePal recently warned that information exposed in a separate breach could support more targeted phishing attempts, showing how leaked identity and contact information can feed follow-on social engineering.

Officials have not disclosed the affected product, attack path or how the activity was detected. Until those details emerge, it remains unclear whether comparable systems face the same exposure.

The records combined durable identity information with military employment details. Even without evidence of misuse, that combination can create identity, social engineering and personnel-targeting risks that outlast the initial incident.

Also read: A recent IDScan breach filing shows how breach scope can evolve as investigations continue, with a regulatory filing confirming 13 million affected people after a much larger dark-web claim had circulated.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.