The Pentagon has confirmed a significant cybersecurity breach affecting the Defense Manpower Data Center (DMDC), impacting the personal information of roughly 3 million individuals. This incident follows closely on the heels of a reported data breach targeting the FBI.
A US defense official revealed that unauthorized access to the DMDC information system occurred between October 2025 and July 2026. The DMDC serves as a primary repository for Pentagon personnel records, containing data on active-duty and reserve troops, civilian employees, contractors, and veterans. The breach is estimated to have affected 2.76 million living individuals and approximately 294,000 deceased individuals.
Details exposed in the breach reportedly include Social Security numbers and information about military and civilian job positions. While defense officials stated that there is currently no evidence of the exposed data being misused, the unencrypted nature of the stolen information is a cause for concern. The DMDC is known to hold records on over 60 million people, meaning the affected subset represents about one in twenty of its total records.
The compromised data, particularly the "occupational specialty" of service members when combined with Social Security numbers, could potentially be exploited by foreign adversaries to gain insights into the deployment and roles of US personnel. No hacking group has publicly claimed responsibility for this breach.
Following the discovery of the unauthorized access, the DMDC implemented immediate remediation measures to address the vulnerability. This incident, alongside the recent FBI data breach, suggests a potential escalation in the sophistication and reach of hacking groups targeting sensitive government information.