A breach at the Pentagon’s Defense Manpower Data Center (DMDC) exposed unencrypted personnel information through unauthorized access lasting from October 2025 until July 16, 2026, when the agency discovered a vulnerability in a file-sharing system. A defense official said the incident affected 2.76 million living people and 294,000 deceased individuals. Exposed information included Social Security numbers and, depending on the individual, names, birth dates, contact information and military occupational specialties.
DMDC patched the vulnerability, restored the system and offered affected individuals one year of credit monitoring and identity-restoration services. Security experts warned that the months-long exposure could enable fraud, targeted deception and identification of government personnel of interest to foreign intelligence services. The incident renewed scrutiny of Pentagon cybersecurity standards and highlighted the need for stronger access monitoring and tested incident-response plans.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Military Times first reported the DMDC incident in late September 2026, citing the breach notification signed by Katie Griffin.
On July 16, 2026, DMDC discovered a vulnerability in its file-sharing system after roughly nine months of unauthorized access. The agency said it immediately initiated privacy and cybersecurity incident-response actions under federal and Defense Department guidelines.
Unauthorized access to the Defense Manpower Data Center’s file-sharing system began in October 2025 and continued until July 16, 2026. The breach exposed unencrypted personnel information affecting approximately 3 million people, including Social Security numbers and, depending on the individual, names, birth dates, contact information and military occupational specialties.
Two people familiar with the incident told Military Times that approximately four million Defense Department personnel may be affected by the DMDC breach. The scope remained unconfirmed, and the Defense Department and DMDC did not immediately respond to questions about the affected population.
A breach notification signed by DMDC Director Katie Griffin described the unauthorized access and exposed personal information. Affected individuals were offered one year of credit monitoring and identity-restoration services.
DMDC patched the file-sharing vulnerability and restored the affected system, according to its breach notification letter. The letter did not specify when those remediation actions occurred.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcenextgov.com
Open sourcemilitarytimes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.