Pentagon Data Breach Exposes Records of 2.76 Million Living Personnel, 294,000 Deceased
A vulnerability in a Defense Manpower Data Center file-sharing system exposed unencrypted personal data for months. The breach affected 2.76 million living individuals and 294,000 deceased individuals, according to TechRadar.
The Defense Manpower Data Center is the Department of War's personnel-data agency. It collects and maintains personnel and workforce data, manages large databases covering military personnel, civilian employees, contractors and others connected to the U.S. defense community, and provides data and analytical services for military operations. Its website says the organization handles more than 60 million records.
The disclosure began to surface roughly two weeks ago, when a person posted a photograph on Reddit of a data breach notification letter they received by mail. In the letter, the DMDC said that on July 16, 2026, a security vulnerability in a DMDC file-sharing system was discovered, allowing unauthorized users to access files. The agency said it immediately updated the file-sharing system to patch the vulnerability and restored the system.
A subsequent investigation determined that someone used the flaw to access servers containing unencrypted personally identifiable information in October 2025. Between then and July 2026, the intruders extracted Social Security numbers, full names, dates of birth, contact information, sex, race and military personnel information such as occupational specialty, according to the notification and TechRadar's report.
A Department of War official confirmed the breach to CNN, saying it affects 2.76 million living individuals and 294,000 deceased ones. The DMDC said it patched the flaw as soon as it discovered it, and it is offering 12 months of credit monitoring services through IDX. The agency also said it was taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system.
The Department of War said there were so far no indications that the files had been misused. TechRadar reported that the stolen data could still be sold on the black market or used for highly tailored phishing emails, potentially tricking victims into sharing login credentials and giving attackers access to more sensitive Department of War servers. CNN reported that occupational specialty information could be especially valuable to foreign nation-state threat actors because it can be combined with Social Security numbers to build a clearer picture of who does what for the U.S. military in various parts of the world.
Some details about the attack remain unclear. TechRadar said it did not know which file-sharing system was targeted or what the flaw was. A few days before the report, secure file-sharing service Kiteworks warned customers to shut down their servers for nine hours in anticipation of an incoming cyberattack. Kiteworks works with government agencies, including U.S. federal, state and local governments, and says defense contractors use its platform to protect controlled unclassified information and federal contract information exchanged with the Department of Defense, though it does not confirm working directly with the agency. The company also says its platform is FedRAMP authorized for federal use. Cybercriminals such as Cl0p are known for targeting this type of service; major breaches at MOVEit and GoAnywhere MFT previously led to data leaks at thousands of organizations.
Editor's Summary The breach at the Defense Manpower Data Center exposed personal and military service data for more than 3 million people, including 2.76 million living individuals. The agency patched the vulnerability and is offering credit monitoring, while the Department of War says it has no indication so far that the data has been misused. The incident highlights the risk from unencrypted files and third-party file-sharing services used across the defense community.