
The Pentagon has confirmed that personal information belonging to more than 3 million people were exposed after unauthorised users gained access to a Defense Manpower Data Center (DMDC) system and remained inside for months.
The breach affected about 2.76 million living people and another 294,000 people who are deceased, and the exposed records included Social Security numbers, names, dates of birth, contact information, and details about the jobs some people held within the U.S. military and Defense Department.
The breach was detected after a long time and while the attackers already gained access. The DMDC says unauthorised users were able to access files between October 2025 and July 16, 2026, giving them access to the system for roughly nine months before the vulnerability was then discovered and patched.
How Did the Pentagon Data Breach Happen?
The breach involved a file-sharing system operated by DMDC, which manages personnel information for the U.S. military and other parts of the Defense Department.
According to a breach notification sent to affected individuals, DMDC discovered a security vulnerability in the system on July 16. An investigation then found that a small number of unauthorised users had accessed files stored on the server between October 2025 and the day the vulnerability was discovered.
While the Pentagon has not publicly disclosed the specific vulnerability that was exploited or identified the people responsible for accessing the system, DMDC says it patched the vulnerability after discovering it and restored the affected system.
What Information Was Exposed?
The files contained unencrypted personally identifiable information, although the exact information exposed differed between individuals.
According to the Pentagon, Social Security numbers were included alongside information that could include names, dates of birth, contact details, sex, race, and military personnel information such as occupational specialties.
The inclusion of military job information has also drawn attention because DMDC holds personnel records covering a wide section of the U.S. defence community, including active-duty and reserve service members, civilian employees, contractors, retirees, veterans, and military family members.
For more context, DMDC maintains more than 60 million personnel records, which means the more than 3 million people affected represent only part of the information held by the agency.
Pentagon Says It Has Found No Evidence of Misuse
The Defense Department says it has not found evidence that the information accessed during the breach has been misused. However, officials have also not publicly explained what the unauthorised users did with the files while they had access to the system.
The nine-month period before the breach was detected is now raising important and urgent questions about how long attackers can remain inside government systems before being discovered.
More importantly, the Pentagon breach also emerged alongside another recent investigation into the FBI’s jobs portal, where sensitive personnel and applicant information were reportedly compromised.
What Happens to People Affected?
DMDC began sending breach notification letters to affected individuals in September. The agency is also providing one year of free credit monitoring and identity restoration services.
For now, several important questions remain unanswered, including who was behind the breach and how the vulnerability first became accessible to them.
For now, the Pentagon has closed the vulnerability that allowed the access. But with unauthorised users able to reach unencrypted personnel files for roughly nine months before they were detected, the incident is putting serious attention on how sensitive government data is stored and monitored.
