A publicly accessible directory tied to U.S. government contractor CMI Management Inc. exposed more than 70,000 files linked to U.S. military installations and personnel. Reports say the contractor, which provides facility management services to the U.S. Army, left records openly available for months through an open directory listing, allowing access to sensitive material including personnel records, contractor documents, maintenance forms, emails, schematics, and photographs taken inside military bases.
The leak created risks including phishing, impersonation, and intelligence gathering against military facilities and staff. Researcher Arkadeep Roy reportedly alerted CISA in 2024 after the exposure was identified following a tip to Cybernews, but the files remained accessible as recently as March 2026, underscoring how long-lived misconfigurations at defense contractors can leave operationally sensitive government data exposed.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
On May 7-8, 2026, news reports disclosed that CMI Management, a U.S. government contractor supporting the Army, had exposed sensitive data connected to U.S. military installations through a misconfigured public-facing directory.
Despite the 2024 notification, the exposed directory remained accessible for months and was still publicly reachable as of March 2026. The leak reportedly included more than 70,000 files such as schematics, personnel records, maintenance forms, emails, contractor records, and photos from inside military bases.
Security researcher Arkadeep Roy notified CISA in 2024 after identifying an open directory listing exposing sensitive CMI Management files tied to U.S. military installations and personnel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.