Hackers stole Pentagon personnel records of over 3 million people

Pentagon

The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025.

In data breach notification letters shared online by affected individuals, the DMDC told affected military personnel that "a small number of unauthorized users" had access to their sensitive data, including personally identifiable information (PII), between October 2025 and July 2026 after exploiting a vulnerability in its file-sharing systems.

The stolen data varies by person and includes Social Security numbers (SSNs), names, dates of birth, contact information, sex, race, and military personnel information.

Pentagon officials told Federal News Network that the data breach affects more than 3 million people, including nearly 2.8 million living individuals and 294,000 "deceased individuals."

"Upon discovery of the security vulnerability, DMDC immediately initiated privacy and cybersecurity incident response actions in accordance with Office of Management and Budget and Department guidelines and policies," the DMDC told affected individuals. "We are taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system."

The Pentagon is also offering 12 months of free credit monitoring services through the IDX data breach and recovery service provider and says affected individuals must enroll by August 19, 2027.

A Pentagon spokesperson was not immediately available to comment when BleepingComputer reached out for more information about the breach.

Founded in 1974, the DMDC is an operational support center that stores more than 60 million military, civilian, contractor, family member, retiree, and veteran records used to authorize benefits and entitlements, as well as training, financial, and other data for the U.S. Department of Defense (DoD). It also operates DoD personnel programs and conducts research and analysis as directed by the Office of the Secretary of Defense (OUSD).

"The services and access to data we provide support so many vital government entities, including the legislative branch, human services, national defense, labor, healthcare, finance, veterans affairs, research, and more," its DMDC says.

This incident follows another massive data breach claimed by the ShinyHunters extortion gang, who breached the FBI's FBIjobs.gov site using an Oracle PeopleSoft zero-day.

ShinyHunters claimed to have stolen several terabytes of data (including names, Social Security numbers, home addresses, and assignments) belonging to "almost ALL FBI Agents," including employee records belonging to members of the FBI Remote Operations Unit, a team involved in hacking operations.

ShinyHunters told BleepingComputer that the FBI breach was not financially motivated and that the group doesn't intend to publish the stolen data or extort the bureau.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Dive deeper

Free tools to verify and analyze what this article covers:

source: BleepingComputer