TWO U.S. federal breaches within a month have exposed a large trove of sensitive data. The Pentagon has disclosed that hackers accessed a Defence Department network used by the Defence Manpower Data Center, compromising personnel records stored there for more than a year. The affected records, reportedly including Social Security numbers, names, addresses, sex, race, and occupational specialty, cover 2.8 million living individuals.
The breached system aggregates data on military, civilian, contractor, retiree, and veteran personnel and their family members. Officials have not explained how the intrusion occurred or whether ransom demands were made, and they say the stolen data has not been used to date, though the agency has not fully detailed how it reached that conclusion.
The incident follows a separate breach that reportedly affected FBI systems, with criminal group ShinyHunters claiming to have stolen records of thousands of current or former FBI employees, including job titles linked to investigations into China and Russia. The group has suggested it does not intend to publish the data, but law enforcement and cybercrime experts warn that such assurances carry little weight from a group with a history of extortion.
Together, these breaches echo a high-profile 2015 incident involving the Office of Personnel Management, where state-linked actors obtained millions of personnel records, including biometric data. The Defence Manpower Data Center emphasises its vast reach, noting it maintains more than 60 million “person records” across the Defence Department. The Pentagon has not provided further details on breach mechanics, contacts with attackers, or ransom activity.