TL;DR: The Pentagon's personnel data system was accessed for roughly nine months before officials discovered and patched the vulnerability, which exposed personally identifiable information tied to more than 3 million people. It contained a particularly sensitive combination of data: Social Security numbers and information about the jobs held by military and civilian personnel – a pairing that raises risks beyond conventional identity theft.
The affected system was run by the Defense Manpower Data Center (DMDC), which manages personnel records across the military and much of the Defense Department's civilian workforce.
The Defense Department said the incident affected 2.76 million living people and another 294,000 who are deceased. DMDC holds more than 60 million personnel records, including records for active-duty troops, reservists, civilian employees, contractors, retirees, veterans and military family members.
"A Defense Manpower Data Center (DMDC) information system experienced unauthorized access of personally identifiable information by a small number of unauthorized users between October 2025 and July 2026. Upon discovery, DMDC immediately remediated the vulnerability," a defense official said.
The statement leaves several major questions unanswered. The department has not said how the intruders got into the system, what vulnerability they used, how much data they viewed or copied, or how the activity went undetected from October 2025 until July 2026. It also has not publicly named a group or country responsible for the intrusion.
The duration of the access is likely to draw attention. Large personnel databases are built to share information across an organization, often with many users, systems and administrative functions involved. That makes them useful for managing payroll, benefits, readiness and workforce records. It can also make them difficult to secure. A flaw in one system can expose data belonging to many groups at once.
DMDC's role makes it an especially attractive target. The organization sits at the center of a broad network of military personnel information. Its records cover people currently serving, people who formerly served, civilian workers and family members. A breach in such a system can create risks that continue long after the technical issue is fixed, particularly when permanent identifiers such as Social Security numbers are involved.
Defense officials said they have not found evidence that the information has been misused. They are offering identity-protection and credit-monitoring services to people affected by the breach. However, a lack of confirmed misuse does not mean the information is no longer at risk. Data can be retained, traded or combined with other material long after an intrusion becomes public.
The Pentagon case comes shortly after the FBI disclosed a separate breach involving FBIJobs.gov, its employment website. The bureau has told employees it is handling the matter as if personal information belonging to all FBI employees may have been compromised. The FBI said the affected system was unclassified and warned employees to be alert for suspicious calls.
Hacking group ShinyHunters later said it would not release FBI-related data it had claimed to possess. "Since the very beginning of this event we have unequivocally and assiduously emphasised this is NOT extortion, this is NOT ransom, this is NOT financially motivated," the group said. "This was all a marketing campaign to protect our business and actively combat disinformation. If we made this statement normally then this much attention to our words and intentions would've never been this widespread."
ABC News said it had not independently verified the group's claims.
For the Pentagon, patching the vulnerability was only the first step. The larger issue is whether the department can determine what happened during the nine-month period of unauthorized access and whether the data was copied or used elsewhere.
