For about nine months, unauthorized users had access to a file-sharing server at the Defense Manpower Data Center (DMDC), the Pentagon's main store of personnel records. The server held unencrypted personally identifiable information (PII). Access ran from October 2025 until DMDC discovered the vulnerability on July 16, 2026. A defense official gave the same breakdown to CNN, ABC News and TIME: 2.76 million living people and 294,000 deceased people were affected, about 3.05 million in total. Outlets round that number differently. BleepingComputer says "over 3 million," Nextgov/FCW says "roughly 3 million," and TechCrunch, citing CNN and Federal News Network, says "about 2.8 million living" and "close to 300,000" deceased. All of them trace back to the same official figure. DMDC has not named the file-sharing product, the vulnerability, or who was behind the access. As of publication, no known cybercrime group had claimed the attack (SecurityWeek).
What Happened
Military Times first reported the breach after reviewing a notification letter dated September 18, 2026 (ABC News, TIME). Recipients later posted copies online, including on Reddit (SecurityWeek, TechCrunch). Nextgov/FCW obtained a copy signed by DMDC Director Katie Griffin.
Key points from the letter, as quoted by several outlets:
- Discovery: "On July 16, 2026, a security vulnerability in a DMDC file sharing system was discovered, which allowed unauthorized users to access files" (SecurityWeek).
- Exposure window: "between October 2025 and the date of discovery, a small number of unauthorized users accessed files on a server containing unencrypted PII" (SecurityWeek). TechCrunch describes the actors as "several unauthorized users."
- Remediation: DMDC says it "immediately updated the file sharing system to patch the vulnerability and the system was restored," and started incident response under OMB and DoD guidelines (SecurityWeek, BleepingComputer, Nextgov/FCW).
- Misuse: The letter says the department "does not have any indications of misuse of the accessed information" (SecurityWeek). A defense official repeated this to ABC News.
The letter does not give a victim count. That figure came from Pentagon officials speaking to the press. The official in CNN's report is identified as a Department of War official (SecurityWeek). Individuals were notified by mail (TIME).
Accessed or stolen? Accounts differ. The official language in the letter and the statement to ABC News says data was "accessed." BleepingComputer and TechCrunch headline the incident as hackers having "stole[n]" the records. No source cites DoD confirming bulk exfiltration or giving a volume of data removed. Readers should treat theft as likely but not officially confirmed.
What Was Taken
Fields varied by person. Across the reporting, the exposed data included:
- Social Security numbers (every source)
- Full names and dates of birth
- Contact information
- Demographic data, including sex and race (BleepingComputer, TechCrunch)
- Military occupational specialties and military personnel and work history (SecurityWeek, Nextgov/FCW, TechTarget)
The letter itself says the files were unencrypted (SecurityWeek, TechCrunch, Nextgov/FCW).
For scale: DMDC holds more than 60 million records on service members, civilians, contractors, family members, retirees and veterans, according to its FY2024 figures (SecurityWeek, BleepingComputer, TIME). The affected group of about 3 million is therefore a fraction of the total. TechCrunch notes it is still more than twice the size of the current active-duty force of about 1.3 million. Public reporting does not say which files or which populations were in the compromised share (TIME).
BleepingComputer reports that the Pentagon is offering 12 months of free credit monitoring through IDX, with enrollment open until August 19, 2027. ABC News more generally reports that identity protection and credit monitoring are being offered.
Why It Matters
Job data makes this more than identity theft. SSNs combined with occupational specialties allow attackers to find people in sensitive roles. ABC News and CNN both frame the incident as a possible national security issue. Experts quoted by TIME say the data makes targeted phishing and other follow-on compromises easier.
DMDC is the military's identity backbone. TechCrunch points out that DMDC is DoD's "leading identity management provider." It links personnel to the smart cards and credentials used to get into Pentagon systems, buildings and bases. Public reporting does not say whether credential systems were touched, but the breach hit the organization that underpins DoD access control.
Dwell time is the real failure. "Three million people may be the headline, but months of unauthorized access to highly sensitive data going undetected is the real warning," Nitay Milner of ORION Security told Nextgov/FCW. TechTarget's analysis says the breach was not a sophisticated attack. It describes a failure of basic controls (encryption, access management and monitoring) at an organization that helps set federal cybersecurity standards, after more than two decades of mandated modernization.
It fits a pattern. TechCrunch calls this the latest in "a spate of thefts involving federal workers' data." Nextgov/FCW and ABC News link it to a separate, concurrent breach notice at the FBI.
The Attack Technique
Few technical details are public:
- Initial access: An unpatched vulnerability in an internet-reachable file-sharing system. DMDC has not identified the product or a CVE (TechTarget, SecurityWeek).
- Data exposure: PII was stored unencrypted on the affected server, so access to the share meant immediate access to readable data.
- Detection gap: About nine months passed between first access and discovery. Nothing in public reporting suggests the activity was caught by monitoring before the vulnerability itself was found.
- Attribution: No actor has been named and no group has claimed the attack (SecurityWeek, TIME).
Analyst note (assessment, not confirmed by sources): Since 2023, managed file transfer and file-sharing platforms have repeatedly been exploited at scale for data theft. Without a named product, defenders cannot tie this incident to a specific known campaign, and they should not assume a link.
What Organizations Should Do
- Inventory and patch every file-sharing and MFT system now. Treat internet-facing file transfer platforms as tier-one assets with emergency patch SLAs, and track vendor advisories for them separately from general patch cycles.
- Encrypt sensitive data at rest on file shares, not only in databases. PII bulk exports in file shares often fall outside database encryption controls. Find them, encrypt them, and set expiry dates on them.
- Monitor file access behavior. Alert on bulk reads, unusual service-account activity, and access from new IPs or ASNs on file-sharing servers. Nine months of undetected access means nobody was baselining file access.
- Minimize what lives on transfer systems. Purge files once transfers finish. A file-sharing server should not serve as long-term storage for SSN-bearing datasets.
- Prepare personnel for targeted social engineering. If your workforce overlaps with DoD (contractors, reservists, veterans), warn staff about pretexting that uses accurate SSNs, birth dates and job roles, and tighten identity verification at help desks.
- Hunt back to October 2025 if you run similar infrastructure. Review file-sharing logs for the full period, not only the last 90 days. Make sure retention is long enough to support that kind of retrospective investigation.
Sources: Pentagon breach exposes failure to follow its own standards | Pentagon Personnel Agency Data Breach Impacts 3 Million ... | Hackers stole Pentagon personnel records of over 3 million people | Hackers stole millions of US military personnel records during ... | Pentagon personnel breach — undetected for months | Pentagon data breach of military personnel raises national security... | Pentagon breach exposed sensitive data on nearly 3 million ... | What to Know About the Pentagon Breach Affecting Millions