Living people affected: Nearly 2.8 million (Source: Federal News Network, Pentagon official (September 2026))
The most worrying numbers in this breach are not only the count of people affected. They are the length of the access window, and the state the data was in. A Pentagon official says unauthorized users had access from October 2025 to July 2026. The records they reached were unencrypted.
Federal News Network reported the incident after a Pentagon official confirmed it. The breach hit the Defense Manpower Data Center (DMDC), which handles identity verification for everyone who holds a Department of Defense ID card.
What happened
The official told Federal News Network that a "small number of unauthorized users" had access to the data. A notice received by one affected person dates the discovery of a file-sharing security vulnerability to July 16. It says the fix came at once.
The exposed records cover nearly 2.8 million living people and 294,000 who have died. They include names, contact details, dates of birth, Social Security numbers and military jobs. The type of data varies by person.
How it worked
The public details are thin. A file-sharing system is software that lets teams store and pass files between people and systems. The notice does not name the product or the flaw, and no CVE ID has been cited. What is reported is that unauthorized users exploited a vulnerability in it.
The second detail matters more. TechCrunch reported that the notice describes the personnel records as unencrypted. Encrypted data is scrambled, so a thief who copies it gets nothing readable without the key. Unencrypted data is readable on sight.
This is analysis, not a finding from the reports. Encryption is not a full defence. If attackers get in through an application that can read the data, it may decrypt the data for them. But it raises the cost of an attack, and here the records were reported to be unencrypted.
The idea: a door is only as safe as what sits behind it
Most security spending goes to keeping intruders out. This breach points to the other half of the problem. Assume a door will fail eventually. Then the questions are how quickly you notice, and what the intruder finds inside.
The sources do not say how the intrusion began, whether access was continuous, or why it went unnoticed. But if access started in October, as the official says, and the flaw was found in July, then it went unnoticed for months. That is an inference, not a reported finding.
The unit that decides who gets into Pentagon systems, buildings and bases held records that were unencrypted. TechCrunch quotes the DMDC's own website: "We make sure that the right people get access and the wrong people don't."
The people who carry the cost are the individuals in those records, not the administrators. A Social Security number cannot be reissued like a password. The Pentagon says it sees no sign of misuse. TechCrunch noted that the department gave no basis for that view. IDX will provide 12 months of credit monitoring.
What remains unanswered
The Pentagon official declined several questions. They included who accessed the data, whether the breach was intentional, and why personal information sits on an unencrypted server. TechCrunch also asked whether officials had heard from the hackers, whose identities are unknown. It received no reply.
TechCrunch places the breach in a run of thefts of federal workers' data. It cites a separate September FBI breach attributed to the ShinyHunters group. The two incidents are not reported as linked. It also notes the 2015 breach of the Office of Personnel Management, which exposed more than 22 million government employees' records and was broadly attributed to China.
What leaders should ask
Any organisation that stores identity records can put four questions to its security team this week.
First, where do our file-sharing and transfer tools sit, and do they touch records about people? Second, if one of them were exploited today, how many months of activity could we reconstruct from logs? Third, which sensitive records are encrypted at rest, and who holds the keys? Fourth, do we still need to keep records of former staff, customers and the deceased?
The reported facts here are a flaw in a file-sharing system, a long access window and unencrypted data. The sources do not show how these connected. Still, each is something an organisation can check in its own systems before an intruder does.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Federal News Network.





