Pentagon Data Breach Exposes Personal Data of More Than 3 Million
Social Security numbers and military job details among compromised information; Pentagon says no misuse has been detected
- Data of about 3.05 million people was affected.
- Social Security numbers were among the exposed information.
- Military occupational details were accessed in some records.
- Pentagon says no evidence of data misuse has been found.
By Anjali Sharma
WASHINGTON – Pentagon officials on Wednesday said that they have found no evidence so far that the compromised information was misused, as unauthorized users had access to the Defense Manpower Data Center system from October 2025 until July 2026.
According to media reports sensitive personal information linked to more than 3 million people was exposed in a Pentagon data breach that went undetected for months, with compromised records including Social Security numbers and details about jobs performed by military and civilian personnel.
Unauthorized users gained access to a Defense Manpower Data Center information system between October 2025 and July 2026, according to a US defence official.
The breach affected 2.76 million living people and another 294,000 deceased individuals.
The scale of the breach has drawn particular attention because some of the records contained information about the work performed by military personnel.
Media reported that “occupational specialty” was among the data accessed in some cases.
The breached information was not encrypted, according to a notification letter reviewed by the network.
“A Defense Manpower Data Center information system experienced unauthorized access of personally identifiable information by a small number of unauthorized users between October 2025 and July 2026. Upon discovery, DMDC immediately remediated the vulnerability,” the defence official said.
The compromised information included Social Security numbers as well as employment-related details belonging to military and civilian personnel, according to news reports.
DMDC holds personnel information covering active-duty and reserve service members, civilian employees, contractors, retirees, veterans and military family members.
The centre maintains more than 60 million personnel records.
The Pentagon has found no evidence that the compromised information has been misused.
A letter from DMDC reviewed said the Pentagon “does not have any indications of misuse” of the data.
Affected individuals are being offered identity-protection services. DMDC is also providing one year of credit monitoring.
The inclusion of military occupational information has added another dimension to the breach beyond identity theft.
Cyber security experts cited by CNN said such information could be combined with other datasets to build profiles of military personnel or assist phishing and intelligence-gathering operations.
Justin Sherman, CEO of advisory firm Global Cyber Strategies, told that access to such records could be used for profiling, phishing, or foreign intelligence approaches if the information fell into the hands of a foreign adversary.
The identity of those responsible for the breach remains unknown.
DMDC said it was taking steps to assess and improve the cybersecurity of its systems.
The disclosure comes as the FBI is dealing separately with a breach involving its jobs website, FBIJobs.gov.
An unidentified threat actor had threatened to publish information including FBI employees’ names, home addresses, personal and work contact details, Social Security numbers, date of birth and emergency contacts, according to sources cited by media reports.
The FBI is operating on the assumption that personal information belonging to every employee may have been compromised.
The hacking group ShinyHunters later told news media groups that it would not release the data it had previously threatened to publish.
Media reports stated it had not independently verified the group’s claim.