THE Defense Manpower Data Center (DMDC), which maintains personnel records for the U.S. Department of Defence, disclosed that a security vulnerability allowed unauthorized access to a file‑sharing server for about nine months. The breach exposed unencrypted personal information and affected an estimated 2.76 million living individuals and 294,000 deceased individuals, according to a Defence Department official cited by the report.
The DMDC noted that it contained at least 60 million records in fiscal year 2024, covering a broad spectrum of personnel, contractors, dependants, retirees and veterans.
The vulnerability was identified on 16 July 2026, after which the DMDC patched the file‑sharing system and restored its services. An investigation determined that a small number of unauthorised users accessed files between October 2025 and the date of discovery. Types of personal data included Social Security numbers and at least one additional identifier such as name, date of birth, contact information, sex, race, and military personnel information including occupational specialty.
In response, DMDC initiated its privacy and cybersecurity incident‑response processes and is offering 12 months of free credit monitoring via IDX, with an enrolment window and code provided to affected individuals; enrolment closes on 19 August 2027. The agency stated that no cybercrime group had claimed responsibility at the time of reporting.