A file-sharing vulnerability at the Defense Manpower Data Center exposed sensitive personnel records for roughly three million people over nine months. The breach leaked unencrypted Social Security numbers and military job data, though defense officials report no confirmed misuse of the information.
The Pentagon disclosed that a security flaw in one of its file-sharing systems went undetected for nearly a year according to disclosures from the Pentagon. The agency manages a repository of over 60 million records covering active-duty personnel, reservists, civil servants, contractors, retirees, veterans, and military family members.
Unauthorized access began in October 2025 and lasted until July 2026. The DMDC discovered the vulnerability on July 16, 2026, and immediately began remediation and system restoration.
Notices mailed to affected individuals starting September 18 detailed the exposure of a server containing unencrypted personally identifiable information (PII).
Breach Hits 2.76 Million Living People
The breach impacted over three million individuals, comprising 2.76 million living people and 294,000 deceased individuals. Compromised files combined permanent identifiers with professional and demographic details.
- Social Security numbers
- Full names and dates of birth
- Contact details and demographic data
- Gender and race information
- Military service data, including specific occupational specialties and job roles
Pentagon Withholds Breach Details
Defense officials launched privacy and cybersecurity incident response actions after finding the vulnerability. The department has not said how the intruders entered the system, what vulnerability they used, how much data they viewed or copied, or how the activity went undetected from October 2025 until July 2026.

No known cybercrime group has taken credit for an attack on the DMDC.
| Date | Event |
|---|---|
| October 2025 | Unauthorized users begin accessing the DMDC file-sharing server |
| July 16, 2026 | Security vulnerability discovered in the file-sharing system |
| July 2026 | DMDC patches the flaw and restores the system |
| September 18, 2026 | Notification letters dispatched to affected individuals |
| September 24, 2026 | Formal notification sent out regarding the breach |
Officials stated that a small group of unauthorized users accessed the files during the nine-month window. Despite fixing the technical flaw, defense authorities have not disclosed the specific file-sharing product involved, the exact nature of the vulnerability, or the identity of the perpetrators.
The Pentagon is offering credit-monitoring and identity-protection services to those affected. This incident coincides with separate cybersecurity events across government networks, including an unclassified breach at FBIJobs.gov.
Formal notification regarding the breach was sent out on September 24, 2026.