Pentagon breach exposes data on 3 million troops and kin

Published

For roughly nine months, someone had access to files holding the Social Security numbers of American service members and their families. The U.S. Department of Defense is notifying millions of people that their personal information was exposed in a breach of the Defense Manpower Data Center (DMDC), the Pentagon office that manages personnel records, ID credentials and benefits for military and civilian staff, veterans and their dependents.

The Pentagon has confirmed the breach affects 2.76 million living individuals, potentially including current and former defense personnel and their dependents, plus 294,000 people who have died, according to an analysis by Malwarebytes. Access reportedly ran from October 2025 to July 2026.

A hole in a file-sharing system

The notification letter sent to affected people says a small number of unauthorized users accessed files on a server containing unencrypted personally identifiable information. The attackers got in by exploiting a vulnerability in a file-sharing system the department hasn't named. No group has been publicly tied to the intrusion.

The exposed data is said to include Social Security numbers, names, dates of birth, sex, race and service details, and some records also carry contact information and occupational specialty. The DMDC maintains more than 60 million records used to determine benefits such as healthcare and retirement.

No sign of misuse is not the same as safe

The Pentagon's position is that it has no indication the data has been misused. As Malwarebytes points out, the department has not explained how it reached that conclusion or what it counts as misuse, and it does not rule out misuse in the future. The stakes run beyond fraud: Malwarebytes notes the data could help foreign intelligence services track U.S. personnel, while birth dates never change and Social Security numbers can be changed only in limited circumstances, so the identity theft risk is lasting.

IntelFusions tracks threat activity against American organizations on its United States profile.

Take the credit monitoring and freeze your credit

The Pentagon is offering 12 months of credit monitoring through IDX. Anyone who receives a letter should take it up, and Malwarebytes also recommends:

The detail that should worry the department most is not the size of the haul but the timeline. A file-sharing hole stayed open on a server holding unencrypted Social Security numbers for most of a year, and the people it exposed are exactly the ones adversaries most want to find.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions