deniz.in

Markets

Weather

Loading weather

· via TechCrunch

Unencrypted Pentagon records of 2.8 million living military personnel stolen in nine-month breach

Hackers exploited a file-sharing vulnerability to steal unencrypted Pentagon personnel records, including Social Security numbers, affecting about 2.8 million living people over roughly nine months.

Unencrypted Pentagon records of 2.8 million living military personnel stolen in nine-month breach

The US government is notifying millions of current and former military service members and civilian staff that hackers stole their personal information from Pentagon personnel records during an intrusion that went on for roughly nine months, according to TechCrunch.

How the breach unfolded

A breach notification issued by the Defense Manpower Data Center (DMDC) and shared on Reddit states that several unauthorized users exploited a security vulnerability in a file-sharing system that has not been named. The activity ran from October 2025 until mid-July 2026.

The stolen data was personally identifiable: Social Security numbers, along with names, dates of birth, sex, race and details of military service. The notification says the records were unencrypted when they were taken.

According to CNN and Federal News Network, a Pentagon official said the breach affects about 2.8 million living people and close to 300,000 deceased individuals. For context, TechCrunch notes that the US military had 1.3 million active-duty service members as of March.

What the DMDC actually holds

Although it is not a household name, the DMDC is one of the Department of Defense's core record-keeping units. It maintains more than 60 million records covering military and civilian staff and their family members, and that data feeds decisions about benefits and entitlements such as healthcare and retirement.

The unit also plays a central role in access control. It acts as the military's primary identity management provider, tying service members, employees and contractors to credentials such as smart cards and passwords that are used to reach Pentagon computer systems, buildings and bases. That role makes the theft of its records more consequential than a typical data breach, since the same organisation sits at the heart of decisions about who is allowed into sensitive systems and facilities.

The official response so far

The Department of Defense, which oversees the DMDC, said it has no indication that the stolen information has been misused, though it did not explain how it reached that conclusion, TechCrunch reports. The hackers have not been identified. TechCrunch says it asked a Pentagon spokesperson whether officials had received any communication from the attackers but received no reply.

The latest in a string of federal breaches

The DMDC incident follows a breach at the FBI earlier in September that has been attributed to the ShinyHunters hacking group. Those hackers told TechCrunch they had taken personal information on most of the FBI's agents and staff, including applicants, and the theft has been described as a counterintelligence disaster given the risk that a foreign government could use such data to profile, target or coerce federal workers. ShinyHunters have said they will not publicly release the stolen FBI data.

Both incidents echo the 2015 breach of the Office of Personnel Management, which was broadly attributed to China and saw hackers steal private records belonging to more than 22 million US government employees, many of whom held security clearances.

Why it matters

This theft combines scale, sensitivity and duration. Nearly three million living people, a figure larger than the entire active-duty military and spanning veterans, civilian staff and reportedly deceased individuals, had unencrypted records including Social Security numbers taken by unknown actors who retained access for most of a year. Because the DMDC underpins identity and access decisions across the Pentagon, the implications go beyond ordinary identity fraud: military personnel are prime targets for foreign intelligence services, and the stolen data could support profiling, phishing or coercion campaigns. The fact that intruders persisted on a file-sharing system for roughly nine months before the activity ended, and that the records were stored unencrypted, points to basic security hygiene gaps inside one of the most heavily defended organisations in the world. Coming weeks after the FBI breach, it also reinforces the impression that federal personnel data has become a recurring systemic weak point rather than an isolated failure.

  • #cybersecurity
  • #data-breach
  • #pentagon
  • #us-government
  • #personal-data

Related posts