Back to Newsroom
Breach

Pentagon Data Breach Exposes Records of Over 3 Million Military-Connected People

A vulnerability in the Pentagon's HR file-sharing system let unauthorized users access sensitive personnel data for more than 3 million service members, retirees, and family members.

Pentagon Data Breach Exposes Records of Over 3 Million Military-Connected People

A breach at the Pentagon's Defense Manpower Data Center (DMDC) has exposed the personal records of more than three million current and former military-connected individuals, after attackers exploited a vulnerability in the agency's file-sharing systems.

What happened

DMDC — the Pentagon office that manages personnel, benefits, and entitlement data for the Department of Defense — is notifying affected individuals that unauthorized users accessed its systems between October 2025 and July 2026. The intrusion exploited a flaw in DMDC's file-sharing infrastructure, giving attackers a window of access to sensitive personnel records before the issue was identified and contained.

Exposed data varies by individual but can include Social Security numbers, full names, dates of birth, contact information, sex, race, and military service details.

Why it matters

The scope is substantial: more than 3 million people are affected, including roughly 2.8 million living individuals and 294,000 deceased individuals whose records remained in DMDC systems. DMDC underpins benefits and entitlement processing for more than 60 million military members, civilians, contractors, family members, retirees, and veterans — meaning a compromise of this scale touches a core piece of defense-sector personnel infrastructure.

This breach also lands amid a broader run of incidents hitting government and defense-adjacent systems, a reminder that legacy HR and records platforms remain attractive, high-value targets for attackers because of the volume and sensitivity of the personal data they hold.

What to do

  • If you've received a DMDC breach notification, enroll in the free 12-month credit monitoring offered through the IDX recovery service before the August 19, 2027 deadline.
  • Treat unsolicited calls, texts, or emails referencing this breach with suspicion — verify any outreach through official DoD or DMDC channels before sharing information.
  • Place a fraud alert or credit freeze with the major credit bureaus if your Social Security number was among the exposed data.
  • Monitor financial accounts and benefits portals for unusual activity in the coming months.
SHARE