Pentagon Personnel Database Was Open for Nine Months. Nearly 3 Million Records Were Exposed

Table of Contents

A U.S. defense official confirmed that unauthorized users reached a Defense Manpower Data Center system between October 2025 and July 2026. The files covered 2.76 million living people and 294,000 deceased. Social Security numbers were in the set, along with details of jobs held by military and civilian personnel. ABC News reported the confirmation on September 28. Military Times had the breach first.

The official’s statement was narrow. “A Defense Manpower Data Center (DMDC) information system experienced unauthorized access of personally identifiable information by a small number of unauthorized users between October 2025 and July 2026. Upon discovery, DMDC immediately remediated the vulnerability.” Defense officials said they have no evidence the data has been misused, and they are offering identity protection and credit monitoring.

What DMDC holds

DMDC is a core personnel store for the Department of Defense. It keeps records on active-duty and reserve troops, civilian employees, contractors, retirees, veterans, and family members, more than 60 million personnel records in all. The breach did not empty that archive. It did reach a slice large enough to include job histories, which is the national-security problem sitting next to the identity-theft problem. A Social Security number is a fraud risk. A job title tied to a unit, a clearance path, or a program office is a targeting list.

Nine months is the other fact. Access ran from October 2025 until the vulnerability was found and patched in July 2026. “A small number of unauthorized users” is not the same as a smashed-and-grab ransomware note. It reads as improper access that persisted. The Pentagon has not said whether those users were outsiders, insiders, or compromised accounts.

The same week at the FBI

The notice landed as the FBI told staff it was treating a breach of its unclassified jobs site, FBIJobs.gov, as if every employee’s personal information had been compromised. Sources told ABC that a threat actor had threatened to publish names, home addresses, personal and work contacts, Social Security numbers, dates of birth, and emergency contacts. The group known as ShinyHunters later told the New York Times and 404 Media it would not release the data, and described the episode as a marketing campaign rather than extortion. ABC News has not verified that claim. The bureau warned staff not to answer suspicious calls.

Two federal personnel systems, one week. Different facts, same exposure: identifiers that do not expire, plus the context of where someone works.

What notification does not answer

Credit monitoring covers new-account fraud. It does not cover a spearphish built from a real billet, a benefits redirect, or a family member contacted with a detail only a personnel file would have. Deceased records in the count matter for a different reason. Survivor benefits, estate fraud, and recycled identifiers sit outside the usual living-person monitoring offer.

For anyone who employs veterans, reservists, or cleared contractors, the practical step is unchanged by the Pentagon’s “no misuse yet.” Treat unexpected calls about military pay, clearance updates, or family benefits as hostile until verified on a known channel. The window was October 2025 through July 2026. The people in those 3 million files will be living with that window longer than the patch.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.