WHAT YOU NEED TO KNOW
  • A Pentagon personnel system breach exposed information belonging to 2.76 million living people and 294,000 deceased individuals.
  • Unauthorized users accessed unencrypted files containing Social Security numbers and other personally identifiable information.
  • The vulnerability existed sometime between October 2025 and July 16, 2026, when officials discovered and immediately patched it.
  • The Pentagon reported no detected misuse and offered affected individuals one year of free credit monitoring.

A security vulnerability inside the Pentagon’s vast personnel records repository exposed sensitive information belonging to millions of U.S. service members and civilian employees, according to multiple media reports.

The breach involved a Defense Manpower Data Center system containing files with personally identifiable information.

The vulnerability affected a file sharing system sometime between October 2025 and July 16, 2026, when it was discovered, Military Times first reported last week.

Officials immediately patched the vulnerability after its discovery, according to a notification letter and the report.

The exposed information covered 2.76 million living people and another 294,000 deceased individuals, ABC News reported Tuesday.

The network cited an unnamed U.S. defense official as its source for those figures.

Pentagon officials did not immediately respond to a request from Stars and Stripes seeking more details about the incident.

That left unanswered the question of who may have accessed the files while the vulnerability remained open.

Following recent reports that Congress is considering a nationwide voter ID requirement for federal elections, do you support requiring voters to show identification before casting a ballot?

By completing the poll, you agree to receive emails from Common Defense, occasional offers from our partners and that you've read and agree to our privacy policy and legal statement.

The breach generated national security concerns because of the sensitive nature of the information stored in the system.

Exposed records included Social Security numbers and military job information, creating a serious personnel security problem for the Pentagon.

A letter dated Sept. 18 informed affected individuals that their data had been involved in the incident. The document was uploaded last week to the Reddit forum r/AirForce and appeared to match information contained in the report.

Two defense officials authenticated the information in the report, according to the source account.

Former Army Sergeant Pleads Guilty to Attempting to Sell U.S. Military Secrets to China
Image Credit: DoW
Cyber-warfare specialists serving with the 175th Cyberspace Operations Group of the Maryland Air National Guard engage in weekend training at Warfield Air National Guard Base, Middle River, Md., Jun. 3, 2017. (U.S. Air Force photo by J.M. Eddins Jr.)

Both the letter and the report said the vulnerability was discovered July 16 and patched immediately.

A subsequent investigation found that a “small number of unauthorized users” had accessed a server holding unencrypted files, the letter stated. Those files contained personally identifiable information, commonly known in defense circles as PII.

The information included Social Security numbers and at least one additional identifying detail. Those additional details could include names, dates of birth, contact information, sex, race or military job information, according to the letter.

The Defense Manpower Data Center serves as the central repository for more than 60 million individual records. Those records cover military personnel, civilian employees, contractors, family members, retirees and veterans.

Information held by the data center includes personnel, manpower, training and financial records.

The scale of that repository, combined with the unencrypted nature of the accessed files, placed millions of records within reach of unauthorized users.

Despite the exposure, the Pentagon has not detected any instances in which the information was misused, according to the letter.

The notification included a link directing affected users to a Pentagon website offering one year of free credit monitoring protection.

The letter described the response undertaken after officials identified the vulnerability. It said the Defense Manpower Data Center launched privacy and cybersecurity incident procedures in line with applicable government and department policies.

“Upon discovery of the security vulnerability, DMDC immediately initiated privacy and cybersecurity incident response actions in accordance with Office of Management and Budget and Department guidelines and policies,” the letter said.

Air Force Must Treat AI as Readiness Priority Across Critical Career Fields, Report Urges
Image Credit: DoW
Airmen analyze metadata to identify any suspicious activity on the network during a cyber threat exercise at Ramstein Air Base, Germany, May 12, 2022. (Jared Lovett/U.S. Air Force)

“We are taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system.”

The incident remained under scrutiny as questions persisted about access to the exposed files. While officials reported no detected misuse, the investigation established that unauthorized users reached a server containing unencrypted personal information.

The affected population extended beyond active service members to civilian employees and other people represented in the massive records repository. The disclosed figures covered more than 3 million living and deceased individuals whose information was exposed.

The notification to affected individuals came roughly two months after the vulnerability was discovered and patched.

It offered credit monitoring while explaining that the Pentagon was assessing and working to strengthen the cybersecurity posture of the Defense Manpower Data Center system.