WHAT YOU NEED TO KNOW
  • Unauthorized users accessed files containing unencrypted Social Security numbers and military personnel information.
  • Approximately four million Department of War personnel may have been affected, according to two people familiar with the incident.
  • DMDC patched the file sharing vulnerability and restored the system after discovering the problem.
  • Affected individuals are being offered one year of credit monitoring and identity restoration services through IDX.

A vulnerability in a Defense Manpower Data Center system allowed unauthorized users to access files containing unencrypted personal information, according to a breach notification letter.

The exposed information included Social Security numbers and military personnel data.

The Defense Manpower Data Center, known as DMDC, discovered the vulnerability on July 16 in a file sharing system.

A notification dated Sept. 18 was sent to an individual whose information appeared in the affected files.

An analysis conducted after the discovery determined that unauthorized users had accessed files stored on a server between October 2025 and July 16, 2026.

Those files contained unencrypted personally identifiable information, also described as PII.

Two defense officials confirmed the authenticity of the notification letter The letter provided the recipient with details about the information that unauthorized users were able to access through the vulnerable system.

The accessed information included the recipient’s Social Security number and at least one additional piece of identifying information.

Following recent reports that Congress is considering a nationwide voter ID requirement for federal elections, do you support requiring voters to show identification before casting a ballot?

By completing the poll, you agree to receive emails from Common Defense, occasional offers from our partners and that you've read and agree to our privacy policy and legal statement.

Possible identifying details included a name, date of birth, contact information, sex or race.

Air Force Pushes Battlefield Boundaries with AI-Driven Targeting Experiment
Image Credit: DoW
First Lt. Maurielle Pankau, a 183rd Air Component Operations Squadron intelligence analyst planner, participates in the Shadow Operations Center — Nellis "Experiment 3" on June 13, 2025. (Airman 1st Class Jennifer Nesbitt/Air Force)

Military personnel information was also among the categories identified in the notification. That information could include an individual’s military occupational specialty, according to the letter.

The notice said the department had no indication that the recipient’s information had been misused.

The notification nonetheless confirmed that unauthorized users had accessed files containing the individual’s sensitive and unencrypted information.

The full scope of the incident remains unclear. Two people familiar with the matter said that approximately four million Department of War personnel may have been affected by the breach.

The War Department and DMDC did not immediately respond to questions about the number of people whose information may have been exposed.

They also did not immediately answer questions about who accessed the files.

DMDC describes itself as the War Department’s central source for identifying, authenticating, authorizing and providing information about personnel.

That role covers individuals during and after their affiliation with the department.

According to the agency’s website, DMDC maintains more than 60 million DoW records. Those records involve military personnel, civilian personnel, contractors, family members, retirees and veterans.

The notification attributed the unauthorized access to a “security vulnerability” in the file sharing system. After discovering the problem, DMDC updated the system to patch the vulnerability and then restored the system, according to the letter.

Affected individuals are being offered one year of credit monitoring and identity restoration services. The services are being provided through IDX, a private company contracted by the DoW.

The notification did not identify evidence that the affected individual’s information had been used improperly. It did confirm, however, that the accessed server held multiple categories of information capable of identifying military personnel and others associated with the department.

The combination of Social Security numbers and additional identifying details was outlined directly in the notice sent to the recipient.

The available additional information could range from basic contact details to military occupational information.

Questions about the incident’s reach remained unanswered by the War Department and DMDC.

The estimate supplied by two people familiar with the incident placed the possible number of affected War Department personnel at approximately four million, while the agency’s final total remained unclear.