www.darkreading.com 9 Oct 2026, 17:21 UTC

Pentagon Data Breach Exposes Records of 3.1 Million People

CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

SHINYHUNTERS once again grabbed headlines after the group claimed to have breached the FBI, alleging data on nearly every FBI employee and applicant from a third-party jobs portal it said it compromised. The claim has been disputed, with authorities and reporters noting no public evidence of a full data dump, while the FBI has publicly warned the group against criminal activity.

A suspected ShinyHunters member was detained in Jordan, reportedly cooperating with officials, and Dutch authorities later arrested another individual connected to the gang. The FBI has said it will pursue attackers vigorously, with footage of a cyber division official stressing consequences for future actions.

Whether these incidents are connected remains unconfirmed by authorities, though discussion has focused on whether the two cases reflect a broader pattern of pressure points between threat actors and government networks.

In a separate but contemporaneous episode, the Pentagon disclosed that access to an unencrypted, Pentagon-run data-centre file-sharing system was gained by unnamed actors for roughly nine months, from October 2025 until 16 July 2026. The breach exposed records for nearly 2.8 million living people and about 294,000 deceased people linked to the US military, including Social Security numbers, names, birth dates, contact details, race, sex, and occupational information.

The Pentagon has offered free credit monitoring and there is no public indication of misuse to date; no attackers have been publicly identified. Adding to the week’s disclosures, the Dutch Institute for Vulnerability Disclosure (DIVD) reported an agentic AI attack on its Zammad-based platform using two zero-days, with data exfiltration from employees under investigation.

Taken together, the episodes underscore persistent risks from unencrypted or poorly segmented services, evolving AI-enabled attacks, and the challenge of attributing incidents across jurisdictions.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline