www.securityweek.com 29 Sept 2026, 12:25 UTC

Pentagon Personnel Records Exposed in Nine Month DMDC Breach

Pentagon Personnel Records Exposed in Nine Month DMDC Breach
CyberSIXT Evidence Panel Source marked as original reporting

THE US Defence Manpower Data Center (DMDC), which stores personnel records for the Pentagon, has begun notifying individuals that their personal information was exposed in a data breach. The DMDC’s notification describes unauthorised access to one of its file-sharing servers for roughly nine months, with the vulnerability discovered on 16 July 2026. The organisation acted promptly to patch the flaw and restore the system.

While the letter does not identify the specific product involved or the exact vulnerability, it notes that between October 2025 and the date of discovery a small number of unauthorised users accessed files on a server containing unencrypted PII. The DMDC said there are no current indications of misuses of the accessed information.

Officials have supplied consolidated figures through a media outlet: the breach impacts 2.76 million living individuals and 294,000 deceased individuals. Exposed records vary by person and include Social Security numbers, names, dates of birth, contact details, demographic data, and military occupational specialties. The DMDC holds at least 60 million records as of fiscal year 2024, covering military and civilian personnel, contractors, family members, retirees and veterans.

It remains unclear who is responsible for the cyberattack, and no credit claim from a known cybercrime group has been reported. DMDC says it has launched privacy and cybersecurity incident response actions following the discovery of the vulnerability.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline