-
A Defense Manpower Data Center system exposed data tied to 2.76 million living people and 294,000 deceased people.
-
The authorized access persisted from October 2025 until July 16, 2026, when the agency found and fixed the flaw.
-
The files held Social Security numbers and job data, but officials say they have found no sign of misuse.

The Pentagon has reportedly confirmed a significant data breach at the Defense Manpower Data Center, exposing personal information of millions of people.
On September 28, a Defense Department official shared updated numbers: 2.76 million individuals still living, plus another 294,000 who’ve passed away. That’s roughly 3.05 million people. The victims may include troops, past troops, civilian staff, contractors, retirees, veterans and family members.
Its site says it holds more than 60 million DoD personnel records. The Pentagon has not said that all of those records were at risk.
Access Lasted About Nine Months
DMDC found a flaw in a file-sharing system on July 16, 2026. The agency then fixed the flaw and brought the system back online. It also began its privacy and cyber response. A review found that unknown users had accessed files from October 2025 through July 16, 2026. The access lasted about nine months.
The notice did not name the users. It also did not say how they got in. Military Times first reported the breach on September 24. The paper reviewed a breach letter dated September 18. T. At first, the size of the breach was not clear.
Military Times cited two defense officials who confirmed that the letter was real. They revealed that the breach may have affected about four million DoD staff and other personnel. The Pentagon later gave a firm count. It said 2.76 million living people and 294,000 deceased people were affected.
Social Security Numbers Exposed
The files held personal data stored without encryption. The data varied from person to person. The breach letter said one victim’s Social Security number was exposed. The data could also include names, birth dates, contact data, sex, race and military job data.
In some cases, that data included an occupational specialty. That mix of data can aid fraud. It can also help a scammer pose as a real person. Criminals can use Social Security numbers and birth dates in some forms of identity theft. Contact data can also help make fake calls, texts or emails look real.
Military job data adds another concern. It may help someone learn who works in a certain role. It could also help build a profile of a service member or defense worker. That has led to concern about possible security or counterintelligence risks.
Officials have not revealed whether the threat actors used the data for spying. They have also not named the people behind the access.
No Known Misuse so Far
The breach notice said the Defense Department found no sign that attackers had misused the exposed data. That does not end the risk. Data such as Social Security numbers and birth dates can stay useful for years.
Criminals can also mix old breach data with public records and other stolen data. The wider challenge of tracking and responding to stolen information is also highlighted in global cyber forces training in a virtual arena to combat a surge in dark web breaches. That can help them build more detailed profiles of victims.
The Pentagon is offering one year of free credit monitoring and identity-restoration services through IDX. People who get a breach letter should use the sign-up details in that letter. They should also check their credit reports for activities they do not know.
They should watch bank, tax and benefit accounts for unusual activity. Any odd charge or account change should get quick attention. People should also be wary of messages tied to military jobs, pay or benefits. Stolen details can make fake messages seem more real.
Questions Remain About the System
The breach also raises questions about how sensitive files were stored and watched. DMDC says it collects and keeps Defense Department data on people and manpower. Its site lists more than 60 million records.
Those records cover military and civilian staff, contractors, family members, retirees and veterans. The breach hit only part of that huge store of data. But the long access window is still a key issue.
Security teams need to spot strange file use fast. They also need clear records of who can open sensitive files. DMDC says it fixed the flaw after finding it. It also started its privacy and cyber response. The department is now looking into the breach. It is also checking the systems tied to the event.
Many details are still not public. The Pentagon has not named the file-sharing product or the exact flaw. It has not said who accessed the files, whether the users copied the data, or what the users may have done with it.
For now, the confirmed facts show a major exposure of personal data. They also show a long gap between the first access and the fix. The next key question is simple: what did the users access, and did they take any of it?