Published Updated

Pentagon Hack Exposes Social Security Numbers Of 2.8 Million Military Personnel
Image: فلسطين الآن

USA · updated 2h ago · 3 min read

Pentagon Hack Exposes Social Security Numbers Of 2.8 Million Military Personnel

Happened

Defense DMDC breach exposed SSNs and personal data for 2.76 million living and 294,000 deceased. Hack lasted months before discovery, with unauthorized access spanning roughly nine months.

Compared

18 outlets told this the same way.

Left out

7 of 9 outlets skipped it: attackers could use SSNs and job details for identity theft and tailored phishing.

18outlets compared

Al-Bawaba NewsArs TechnicaBitdefenderCNNCyberSecurityNewsIsrael DefenseMasrawyMauqiʿ Lubnan al-Kabir

Pentagon records stolen

The Pentagon is informing more than 2 million current and former military members that their personnel records were stolen over a monthslong compromise of one of its networks, and the breach exposed Social Security numbers, names, addresses, sex, race, and occupational specialty. The Defense Manpower Data Center (DMDC) said unauthorized users exploited a vulnerability in an unspecified file-sharing system for several months between October 2025 and mid-July 2026, and the notice letter said the affected personnel records were unencrypted.

The Pentagon told TechCrunch that the breach affects about 2.8 million living people and close to 300,000 people who are deceased, and the DMDC letter posted on Reddit described the incident as spanning October 2025 to mid-July 2026. The Pentagon also said it does not have any indication that the information was misused, while the breach notification letter said DMDC immediately updated the file sharing system to patch the vulnerability and restored the system after discovering it on July 16, 2026.

Image from Al-Bawaba News
Al-Bawaba NewsAl-Bawaba News

How long, what data

The breach began in October 2025 after “a small number of unauthorized users” exploited a vulnerable server run by the Defense Manpower Data Center, and the DMDC identified and patched the vulnerability in July 2026 after the intrusion persisted for eight months. The Defense Department official told CNN and Federal News Network that the breach affects about 2.8 million living people and close to 300,000 people who are deceased, and the DMDC website said it maintains over 60 million records for service members, civilian staff, and their family members.

The DMDC notification letter described the stolen information as including Social Security numbers, names, dates of birth, contact information, sex, race, and military personnel information such as occupational specialty. The breach letter also said DMDC “immediately remediated the vulnerability,” and the Pentagon said it was offering 12 months of credit monitoring services through IDX after the notification began reaching victims through a breach letter dated September 18.

Image from Ars Technica
Ars TechnicaArs Technica

Aftermath and scrutiny

The Pentagon’s breach came after the ransomware group ShinyHunters claimed it hacked into FBI systems and stole records of thousands of the agency’s current or former employees, and Ars Technica said an FBI official called on group members to turn themselves in. The TechCrunch report said the ShinyHunters hackers told it they had taken the personal information of most of the FBI’s agents and staffers, including applicants, and the breach has been billed as a “counterintelligence disaster” amid risks that a foreign government could profile or coerce federal workers.

The Defense Department said it has no indication of misuse of the stolen information at this time, while the TechSpot account said the statement left major questions unanswered about how intruders got in, what vulnerability they used, how much data they viewed or copied, and how the activity went undetected. The DMDC breach also raised scrutiny of centralized personnel databases, and TechCrunch said the DMDC provides the military’s “leading identity management provider,” linking active service members, employees, and contractors to credentials such as smart cards and passwords used to access Pentagon computer systems, buildings, and bases.