Skip to content
Security & Trust

A file-sharing flaw put unencrypted military records of 3 million people at risk

The Pentagon's identity unit says intruders had access from October 2025 to July 2026. The records were unencrypted.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
A file-sharing flaw put unencrypted military records of 3 million people at risk

AI-generated image for WebPulse. About our images

Key finding

Living people affected: Nearly 2.8 million (Source: Federal News Network, Pentagon official (September 2026))

The most worrying numbers in this breach are not only the count of people affected. They are the length of the access window, and the state the data was in. A Pentagon official says unauthorized users had access from October 2025 to July 2026. The records they reached were unencrypted.

Federal News Network reported the incident after a Pentagon official confirmed it. The breach hit the Defense Manpower Data Center (DMDC), which handles identity verification for everyone who holds a Department of Defense ID card.

What happened

The official told Federal News Network that a "small number of unauthorized users" had access to the data. A notice received by one affected person dates the discovery of a file-sharing security vulnerability to July 16. It says the fix came at once.

The exposed records cover nearly 2.8 million living people and 294,000 who have died. They include names, contact details, dates of birth, Social Security numbers and military jobs. The type of data varies by person.

Nearly 2.8 million
Living people affected
Source: Federal News Network, Pentagon official (September 2026)
294,000
Deceased people affected
Source: Federal News Network, Pentagon official (September 2026)
More than 60 million
Records DMDC maintains
Source: Federal News Network (September 2026)

How it worked

The public details are thin. A file-sharing system is software that lets teams store and pass files between people and systems. The notice does not name the product or the flaw, and no CVE ID has been cited. What is reported is that unauthorized users exploited a vulnerability in it.

The second detail matters more. TechCrunch reported that the notice describes the personnel records as unencrypted. Encrypted data is scrambled, so a thief who copies it gets nothing readable without the key. Unencrypted data is readable on sight.

This is analysis, not a finding from the reports. Encryption is not a full defence. If attackers get in through an application that can read the data, it may decrypt the data for them. But it raises the cost of an attack, and here the records were reported to be unencrypted.

The idea: a door is only as safe as what sits behind it

Most security spending goes to keeping intruders out. This breach points to the other half of the problem. Assume a door will fail eventually. Then the questions are how quickly you notice, and what the intruder finds inside.

The sources do not say how the intrusion began, whether access was continuous, or why it went unnoticed. But if access started in October, as the official says, and the flaw was found in July, then it went unnoticed for months. That is an inference, not a reported finding.

The unit that decides who gets into Pentagon systems, buildings and bases held records that were unencrypted. TechCrunch quotes the DMDC's own website: "We make sure that the right people get access and the wrong people don't."

The people who carry the cost are the individuals in those records, not the administrators. A Social Security number cannot be reissued like a password. The Pentagon says it sees no sign of misuse. TechCrunch noted that the department gave no basis for that view. IDX will provide 12 months of credit monitoring.

What remains unanswered

The Pentagon official declined several questions. They included who accessed the data, whether the breach was intentional, and why personal information sits on an unencrypted server. TechCrunch also asked whether officials had heard from the hackers, whose identities are unknown. It received no reply.

TechCrunch places the breach in a run of thefts of federal workers' data. It cites a separate September FBI breach attributed to the ShinyHunters group. The two incidents are not reported as linked. It also notes the 2015 breach of the Office of Personnel Management, which exposed more than 22 million government employees' records and was broadly attributed to China.

October 2025 to July 2026
Window of unauthorized access
Source: Federal News Network, Pentagon official and breach notice (September 2026)

What leaders should ask

Any organisation that stores identity records can put four questions to its security team this week.

First, where do our file-sharing and transfer tools sit, and do they touch records about people? Second, if one of them were exploited today, how many months of activity could we reconstruct from logs? Third, which sensitive records are encrypted at rest, and who holds the keys? Fourth, do we still need to keep records of former staff, customers and the deceased?

The reported facts here are a flaw in a file-sharing system, a long access window and unencrypted data. The sources do not show how these connected. Still, each is something an organisation can check in its own systems before an intruder does.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Federal News Network.

Share this insight