Hackers stole millions of US military personnel records during months-long data breach
First reported by TechCrunch ·
Your personally identifiable information, including Social Security numbers, is now at risk of misuse due to a government data breach.
Millions of U.S. military personnel and staff have been notified of a data breach affecting their personal information, including Social Security numbers, names, dates of birth, and service details. The breach occurred over several months, from October 2025 to mid-July 2026, through an unspecified file-sharing system within the Pentagon's Defense Manpower Data Center (DMDC). The DMDC maintains records for over 60 million individuals to manage benefits and entitlements and serves as the military's identity management provider. Approximately 2.8 million living individuals and nearly 300,000 deceased individuals are impacted. The unencrypted records were exposed due to a security vulnerability. The Department of Defense has stated there is no indication of misuse, but the method of their conclusion is unclear. This incident follows other recent data thefts involving federal workers' information, including a breach at the FBI attributed to the ShinyHunters hacking group.
This breach highlights a persistent vulnerability in how sensitive government data is protected, particularly unencrypted personnel records. The DMDC's role in identity management means this information could be a treasure trove for state-sponsored actors or sophisticated criminal organizations looking to compromise national security or conduct large-scale identity theft. The repeated nature of these breaches suggests a systemic issue in the government's cybersecurity posture, despite warnings and past incidents.
The exposure of 2.8 million individuals' data, including those with security clearances, presents a significant counterintelligence risk. Foreign adversaries could leverage this information for profiling, coercion, or espionage, potentially impacting active service members and critical national security operations. The lack of immediate indication of misuse by the DOD, coupled with the unencrypted nature of the data, raises questions about their incident response and the true extent of the ongoing threat.
AI-written summary. May contain errors.