Skip to main content

Pentagon Personnel Agency Data Breach Impacts 3 Million People

0
High
Breach
Published: 09/29/2026 (09/29/2026, 12:25:12 UTC)
Source: SecurityWeek

Description

The Defense Manpower Data Center (DMDC), which manages personnel records for the Department of Defense, suffered a data breach exposing personal information of approximately 3 million individuals. Unauthorized access occurred via a file-sharing server vulnerability that was active for about nine months before being patched in July 2026. Exposed data included unencrypted personally identifiable information (PII) such as Social Security numbers, names, dates of birth, contact details, demographic data, and military occupational specialties. There are currently no indications of misuse of the accessed information. The breach affects both living and deceased individuals, but the responsible party remains unknown.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 12:32:52 UTC

Technical Analysis

Between October 2025 and July 2026, unauthorized users accessed files on a DMDC file-sharing server due to a security vulnerability. The vulnerability was discovered and patched on July 16, 2026. The exposed data involved unencrypted PII of approximately 2.76 million living individuals and 294,000 deceased individuals, including sensitive military and personal information. The DMDC initiated privacy and cybersecurity incident response actions upon discovery. The specific file-sharing product and vulnerability details were not disclosed, and no known cybercrime group has claimed responsibility.

Potential Impact

The breach compromised sensitive unencrypted personal and military-related information of about 3 million individuals, including Social Security numbers and other PII. This exposure could potentially lead to identity theft or other privacy risks if the data is misused, although no misuse has been detected so far. The affected records span military personnel, civilians, contractors, family members, retirees, and veterans.

Defensive Guidance

The vulnerability in the DMDC file-sharing system was identified and patched on July 16, 2026. The system was restored and incident response actions were initiated. At this time, there are no indications of misuse of the exposed data. Individuals affected have been notified. No further immediate action is specified by the DMDC; monitoring for misuse of personal information is advisable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/pentagon-personnel-agency-data-breach-impacts-3-million-people/","fetched":true,"fetchedAt":"2026-09-29T12:32:48.002Z","wordCount":1020}

Threat ID: 6abbaff0f7a7c541065eab78

Added to database: 09/29/2026, 12:32:48 UTC

Last enriched: 09/29/2026, 12:32:52 UTC

Last updated: 09/29/2026, 18:00:42 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses