A breach involving a U.S. Department of Defense personnel database exposed sensitive personal information linked to more than 3 million people, including military personnel, civilian employees and others connected to the U.S. defense community.
According to a U.S. defense official, the incident involved unauthorized access to information held by the Defense Manpower Data Center (DMDC). The exposed records included Social Security numbers and details about individuals' military or civilian jobs.
Nearly 3 Million Living and Deceased Individuals Affected
The Pentagon said the breach affected approximately 2.76 million living individuals and 294,000 deceased individuals.
The compromised information reportedly included:
Names
Contact information
Dates of birth
Social Security numbers
Military job specialties
Other personnel records
The DMDC maintains personnel information covering active-duty and reserve service members, civilian employees, contractors, retirees, veterans and military family members.
Unauthorized Access Lasted for Months
Defense officials said unauthorized users had access to the affected information between October 2025 and July 2026.
The vulnerability was discovered on July 16 in a file-sharing system. The Pentagon said it subsequently remediated the vulnerability and secured the affected system.
Military Times previously reported that the affected files contained unencrypted personally identifiable information, including Social Security numbers and military personnel data.
No Evidence of Misuse Reported So Far
While the scale of the exposed information has raised concerns, officials said there is no evidence so far that the exposed data has been misused.
The Pentagon is assessing the incident and has said affected individuals are being provided with identity-protection and credit-monitoring resources.
The distinction is important: current reporting establishes unauthorized access to the database, but authorities have not publicly established that the information was subsequently used for fraud, espionage or other malicious activity.
National Security Concerns
The incident is particularly sensitive because the database contains information about people associated with the U.S. military and Defense Department.
Beyond conventional identity-theft risks, information about military and civilian job roles could potentially provide additional intelligence value if obtained and combined with other datasets.
The DMDC reportedly maintains more than 60 million personnel records, making the security of its systems an important component of the Pentagon's broader personnel-data infrastructure.
Comes Amid Other Federal Cybersecurity Incidents
The Pentagon breach comes during a period of heightened scrutiny of cybersecurity across U.S. government systems.
The FBI is separately investigating an alleged compromise involving FBIJobs.gov, where hackers claimed to have obtained personal information belonging to FBI employees and job applicants. The FBI has confirmed an investigation, while the full scope and source of that incident remain under assessment.
The incidents highlight the risks associated with large government databases containing sensitive personal information and the importance of access controls, encryption, vulnerability management and continuous monitoring.
Why the Pentagon Breach Matters
The incident demonstrates that a cybersecurity vulnerability does not necessarily need to involve classified military systems to create significant consequences. Large personnel databases can contain highly sensitive information that can expose individuals to identity theft, targeted attacks and other risks.
For government agencies and organisations managing sensitive employee data, the breach reinforces the importance of strong access controls, encrypted data storage, secure file-sharing systems, vulnerability remediation and continuous security monitoring.
The Pentagon continues to assess the incident, while affected individuals are being notified and offered protective services.
