Hackers Stole Millions of U.S. Military Personnel Records in Months-Long Breach
The U.S. government is notifying about 2.8 million living military personnel and nearly 300,000 deceased people that their personal data was stolen from a Pentagon records system in a breach lasting from October 2025 to July 2026.
A breach notification from the Defense Manpower Data Center shared on Reddit said unauthorized users exploited a security vulnerability in an unspecified file-sharing system over several months between October 2025 and mid-July 2026. The exposed records were unencrypted and included Social Security numbers, names, dates of birth, sex, race and other information about military service.
According to CNN and Federal News Network, a Pentagon official said the breach affects about 2.8 million living people and close to 300,000 people who are deceased. The U.S. military had 1.3 million active service members as of March, according to TechCrunch.
The DMDC is one of the Department of Defense's record-keeping units. It maintains more than 60 million records for U.S. military and civilian staff and their family members to help determine benefits and entitlements such as healthcare and retirement. It also serves as the military's leading identity management provider, linking active service members, employees and contractors to credentials such as smart cards and passwords used to access Pentagon computer systems, buildings and bases. Its website says it makes sure that the right people get access and the wrong people do not, and that security of identity information is paramount.
The Department of Defense, which oversees the DMDC, said it does not have any indication that the information was misused, but it did not say how it reached that conclusion. TechCrunch contacted a Pentagon spokesperson to ask whether officials had any communications from the hackers, whose identities are not known, and did not receive a response.
The breach follows a separate incident at the FBI earlier in September that was attributed to the ShinyHunters hacking group. The hackers told TechCrunch they had taken the personal information of most of the FBI's agents and staffers, including applicants. That breach has been described as a counterintelligence disaster because a foreign government could obtain and use the information to profile, target or coerce federal workers into handing over sensitive information. ShinyHunters have said they will not publicly release the stolen FBI data.
Both the FBI and DMDC breaches mirror earlier thefts of government personnel records. In 2015, a breach of the U.S. Office of Personnel Management was broadly attributed to China. The theft allowed hackers to steal the private records of more than 22 million U.S. government employees, many of whom had security clearances.
Editor's Summary
The breach at the Defense Manpower Data Center exposed unencrypted personal data for about 2.8 million living military personnel and staff and nearly 300,000 deceased people, according to a Pentagon official cited by CNN and Federal News Network. The Department of Defense says it has no indication the data was misused, but the incident adds to recent concerns about federal personnel records after a separate FBI breach attributed to ShinyHunters. The DMDC system supports benefits and identity credentials for military personnel, making the exposure significant for both privacy and security.