Pentagon Data Breach Exposed Unencrypted Social Security Numbers for Months, Affecting More Than 3 Million People
The DMDC says files were accessible from October 2025 until the vulnerability was patched in July 2026; affected people are being offered one year of free credit monitoring

For roughly nine months, unencrypted personal information including Social Security numbers was accessible to unauthorised users through a DMDC file-sharing system. The Defense Department did not find the vulnerability until 16 July.
The exposure affected 2.76 million living people and another 294,000 deceased people, a US defence official said. The files belonged to the Defense Manpower Data Center, or DMDC, one of the Pentagon's main repositories for personnel, manpower, training and financial records.
What the Breach Letter Reveals
The notification letter, dated 18 September, provides details of the incident. A copy was posted to the r/AirForce subreddit, and it appears to match a notification letter whose authenticity was confirmed by two defence officials, according to Military Times.
According to the letter, a follow-up investigation found that a 'small number of unauthorized users' had accessed a server containing unencrypted files. The access occurred from October 2025 until the vulnerability in the file-sharing system was discovered and patched on 16 July 2026.
The types of personal information varied by individual. The notification letter said they could include a Social Security number and at least one additional identifier, such as a name, date of birth, contact information, sex, race or military job information.
'Upon discovery of the security vulnerability, DMDC immediately initiated privacy and cybersecurity incident response actions in accordance with Office of Management and Budget and Department guidelines and policies,' the letter said.
Who Was Affected and What They Are Being Offered
The DMDC holds more than 60 million records covering military and civilian personnel, contractors, retirees, veterans and family members. Officials have not provided a breakdown showing which groups make up the 2.76 million living people whose information was affected.
Early estimates were higher. Before the department provided its later figure, two people familiar with the incident said that about four million Defense Department personnel might be affected.
Affected individuals are being directed to a Pentagon site offering one year of free credit monitoring and identity-restoration services. The letter states that no misuse of the data has been detected so far.
'We are taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system,' the DMDC wrote.
Questions the Pentagon Has Yet To Answer
Several points remain unexplained. The department has not said who accessed the files, why the files contained unencrypted information, or why notification letters were dated more than two months after the vulnerability was fixed.
A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current & former military personnel, raising counterintelligence concerns among national security experts.https://t.co/Azu5m4RUBa
— Zachary Cohen (@ZcohenCNN) September 25, 2026
Pentagon officials did not immediately respond when asked who may have accessed the data. In its statement, the department said a DMDC information system experienced unauthorised access by 'a small number of unauthorized users' between October 2025 and July 2026.
'Upon discovery, DMDC immediately remediated the vulnerability,' the official added.
The breach is not the first to hit US government personnel records. In July 2015, the Office of Personnel Management announced that the Social Security numbers of 21.5 million people had been stolen from its background investigation databases.
The exposure of Social Security numbers creates a potential risk of identity theft and fraud, although the Pentagon says it has not detected misuse of the affected information.
The files also contained military job information, and the scope and sensitivity of those records could raise national security concerns, particularly because they included details about the work performed by military and civilian personnel.
For those affected, questions remain about who accessed their information and how long the available monitoring and protection will need to remain in place.
© Copyright IBTimes 2026. All rights reserved.























