Pentagon Personnel Agency Data Breach Impacts 3 Million People
The Defense Manpower Data Center (DMDC), which manages personnel records for the Department of Defense, suffered a data breach exposing personal information of approximately 3 million individuals. Unauthorized access occurred via a file-sharing server vulnerability that was active for about nine months before being patched in July 2026. Exposed data included unencrypted personally identifiable information (PII) such as Social Security numbers, names, dates of birth, contact details, demographic data, and military occupational specialties. There are currently no indications of misuse of the accessed information. The breach affects both living and deceased individuals, but the responsible party remains unknown.
AI Analysis
Technical Summary
Between October 2025 and July 2026, unauthorized users accessed files on a DMDC file-sharing server due to a security vulnerability. The vulnerability was discovered and patched on July 16, 2026. The exposed data involved unencrypted PII of approximately 2.76 million living individuals and 294,000 deceased individuals, including sensitive military and personal information. The DMDC initiated privacy and cybersecurity incident response actions upon discovery. The specific file-sharing product and vulnerability details were not disclosed, and no known cybercrime group has claimed responsibility.
Potential Impact
The breach compromised sensitive unencrypted personal and military-related information of about 3 million individuals, including Social Security numbers and other PII. This exposure could potentially lead to identity theft or other privacy risks if the data is misused, although no misuse has been detected so far. The affected records span military personnel, civilians, contractors, family members, retirees, and veterans.
Mitigation Recommendations
The vulnerability in the DMDC file-sharing system was identified and patched on July 16, 2026. The system was restored and incident response actions were initiated. At this time, there are no indications of misuse of the exposed data. Individuals affected have been notified. No further immediate action is specified by the DMDC; monitoring for misuse of personal information is advisable.
Pentagon Personnel Agency Data Breach Impacts 3 Million People
Description
The Defense Manpower Data Center (DMDC), which manages personnel records for the Department of Defense, suffered a data breach exposing personal information of approximately 3 million individuals. Unauthorized access occurred via a file-sharing server vulnerability that was active for about nine months before being patched in July 2026. Exposed data included unencrypted personally identifiable information (PII) such as Social Security numbers, names, dates of birth, contact details, demographic data, and military occupational specialties. There are currently no indications of misuse of the accessed information. The breach affects both living and deceased individuals, but the responsible party remains unknown.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Between October 2025 and July 2026, unauthorized users accessed files on a DMDC file-sharing server due to a security vulnerability. The vulnerability was discovered and patched on July 16, 2026. The exposed data involved unencrypted PII of approximately 2.76 million living individuals and 294,000 deceased individuals, including sensitive military and personal information. The DMDC initiated privacy and cybersecurity incident response actions upon discovery. The specific file-sharing product and vulnerability details were not disclosed, and no known cybercrime group has claimed responsibility.
Potential Impact
The breach compromised sensitive unencrypted personal and military-related information of about 3 million individuals, including Social Security numbers and other PII. This exposure could potentially lead to identity theft or other privacy risks if the data is misused, although no misuse has been detected so far. The affected records span military personnel, civilians, contractors, family members, retirees, and veterans.
Defensive Guidance
The vulnerability in the DMDC file-sharing system was identified and patched on July 16, 2026. The system was restored and incident response actions were initiated. At this time, there are no indications of misuse of the exposed data. Individuals affected have been notified. No further immediate action is specified by the DMDC; monitoring for misuse of personal information is advisable.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/pentagon-personnel-agency-data-breach-impacts-3-million-people/","fetched":true,"fetchedAt":"2026-09-29T12:32:48.002Z","wordCount":1020}
Threat ID: 6abbaff0f7a7c541065eab78
Added to database: 09/29/2026, 12:32:48 UTC
Last enriched: 09/29/2026, 12:32:52 UTC
Last updated: 09/29/2026, 18:00:42 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.