Skip to content
Cybersecurity

Pentagon Data Breach Exposes Information of More Than 3 Million People

Defense Manpower Data Center breach affects more than 3 million people

A Defense Manpower Data Center (DMDC) information system has suffered a data breach affecting more than 3 million people, exposing sensitive personal information connected to the U.S. defense establishment. A U.S. defense official said the affected population includes 2.76 million living people and about 294,000 deceased individuals.

The breach involved unauthorized access to files containing personally identifiable information. The DMDC discovered the underlying vulnerability on July 16, 2026, after unauthorized users had reportedly accessed information from October 2025 through July 2026.

DMDC Files Contained Sensitive Personnel Data

The compromised files contained unencrypted personal information. Depending on the individual, exposed records included names, Social Security numbers, dates of birth, contact information and military personnel information, including occupational specialties.

The DMDC maintains personnel information covering active-duty and reserve service members, civilian employees, contractors, retirees, veterans and military family members. Its systems contain more than 60 million Defense Department records.

File-Sharing Vulnerability Allowed Unauthorized Access

According to notification letters sent to affected individuals, a security vulnerability in a DMDC file-sharing system allowed unauthorized users to access files stored on an affected server.

DMDC discovered the vulnerability on July 16 and subsequently updated the file-sharing system to patch the issue and restore the system. The department also initiated privacy and cybersecurity response measures.

The Pentagon has not publicly identified who accessed the files or disclosed detailed technical information about the vulnerability.

Pentagon Reports No Confirmed Misuse So Far

Despite the scale of the exposure, the Defense Department said it has no evidence so far that the compromised information has been misused. The department is providing affected individuals with identity-protection resources and one year of credit monitoring and identity-restoration services through IDX.

The incident was initially reported through individual breach notifications before the Pentagon disclosed the broader scope. Earlier reporting had suggested that the number of potentially affected Defense Department personnel could be higher, but the Pentagon's later figure puts the confirmed affected population at more than 3 million.

Breach Raises Concerns Over Government Personnel Data

The exposure is significant because the affected records combine personal identifiers with information about military and civilian personnel. In some cases, occupational information was included alongside Social Security numbers and other identifying details.

The breach also illustrates the risks surrounding supporting systems such as file-sharing infrastructure, where sensitive information can remain accessible outside an organisation's primary personnel databases.

The investigation into the incident remains ongoing, while the Pentagon continues to assess the affected records and strengthen security controls around the DMDC system.