THE Pentagon confirms a data breach at the Defence Manpower Data Centre (DMDC), a DoD organisation that manages personnel records, ID credentials and benefits entitlements for military and civilian staff, veterans and their families. The incident is said to have exposed personal information for millions of people, with reports stating attackers accessed data from October 2025 to July 2026.
The breach is reported to affect 2.76 million living individuals and 294,000 deceased individuals, though the Pentagon notes it has “no indication” of misuse at this stage. The exposed data is described as including social security numbers, names, dates of birth, sex, race and service details, with some records also containing contact information and occupational specialty.
The attackers purportedly gained access by exploiting a security vulnerability in an unspecified file-sharing system, and while the Pentagon has not detailed how it reached its assessment of misuse, it has not ruled out future abuse of the disclosed information.
In response, the Pentagon is offering 12 months of credit monitoring through IDX and advises affected individuals to consider placing a credit freeze with the three major credit bureaus. The article also recommends obtaining an IRS Identity Protection PIN to prevent fraudulent federal tax returns, staying vigilant for phishing attempts, verifying requests via official channels, using unique passwords and multi‑factor authentication, and reviewing privacy settings on devices and apps. The guidance highlights ongoing risks, including identity theft and the potential for misuse of long‑lived data like dates of birth and SSNs.