TL;DR: The Pentagon’s personnel records system was accessed for about nine months before officials discovered and fixed the security flaw, exposing personal information on more than three million people. It contained a particularly sensitive combination of data: Social Security numbers and information about the jobs of military and civilian personnel – a pairing that poses risks beyond traditional identity theft.
The affected system was operated by the Defense Manpower Data Center (DMDC), which manages personnel records for the entire military and much of the Defense Department’s civilian workforce.
According to the Defense Ministry, the incident affected 2.76 million living people and another 294,000 deceased. DMDC has more than 60 million personnel records, including records on active-duty troops, reservists, civilian employees, contractors, retirees, veterans and military families.
“An information system at the Defense Manpower Data Center (DMDC) experienced unauthorized access to personal data by a small number of unauthorized users between October 2025 and July 2026. Upon discovery, DMDC immediately remedied the vulnerability,” a defense official said.
The declaration leaves several important questions unanswered. The ministry has not said how the intruders got into the system, what vulnerability they exploited, how much data they viewed or copied, or how the activity went undetected from October 2025 to July 2026. It also has not publicly named a group or country responsible for the break-in.
The length of access is likely to attract attention. Large human resources databases are created to share information across the organization, often involving many users, systems, and administrative functions. This makes them useful for managing payroll, benefits, on-call and workforce records. They can also be difficult to secure. A flaw in a system can result in multiple groups’ data being exposed at the same time.
DMDC’s role makes it a particularly attractive target. The organization is at the center of a broad network for information for military personnel. The records include individuals currently serving, those previously serving, civilian workers, and family members. A breach of such a system can result in risks that persist long after the technical issue has been resolved, particularly when it comes to persistent identifiers such as Social Security numbers.
Defense officials said they found no evidence that the information had been misused. They provide identity protection and credit monitoring services to those affected by the breach. However, the absence of confirmed misuse does not mean that the information is no longer at risk. Data can be stored, traded, or combined with other material long after a breach becomes public.
The Pentagon case comes shortly after the FBI disclosed a separate breach of FBIJobs.gov, its employment website. The FBI has told employees that it is treating the matter as if personal information of all FBI employees had been compromised. The FBI said the affected system was unclassified and warned employees to be alert for suspicious calls.
The hacking group ShinyHunters later said it would not release FBI-related data it had claimed to have. “Since the beginning of this event, we have stated unequivocally and diligently that this is NOT extortion, that this is NOT a ransom and that this is NOT financially motivated,” the group said. “This was all a marketing campaign to protect our company and actively combat disinformation. If we had made this statement normally, so much attention to our words and intentions would never have been so widespread.”
ABC News said it had not independently verified the group’s claims.
For the Pentagon, fixing the vulnerability was only the first step. The bigger question is whether the department can determine what happened during the nine-month period of unauthorized access and whether the data was copied or used elsewhere.