Pentagon data breach exposed Social Security numbers of 3.1 million current and former troops
Unauthorized users spent nine months inside a Pentagon personnel database before the intrusion was discovered in July, and formal notifications to the roughly 3.1 million people affected did not begin until last month.

The Pentagon has begun notifying roughly 3.1 million current and former U.S. military personnel, along with family members and civilian employees, that their Social Security numbers and other personal data were exposed in a breach of a Defense Department personnel system that went undetected for nine months.
The intrusion struck the Defense Manpower Data Center, the Pentagon's central repository for personnel and manpower records, according to reporting Tuesday by TechCrunch, which cited figures attributed to CNN and Federal News Network. Unauthorized users accessed an unencrypted file-sharing system on a DMDC server between October 2025 and July 16, 2026, before the vulnerability was found and patched. Notification letters to affected individuals did not go out until September 18, more than two months after discovery.
The numbers
The Pentagon has told reporters that approximately 2.8 million living individuals and nearly 300,000 deceased people had information exposed in the breach, a more precise accounting than the figure of up to four million that Military Times first reported on September 24, when it disclosed the existence of the notification letters and described the breach's scope as still unclear. For context, the Defense Department counted roughly 1.3 million active-duty service members as of March 2026, meaning the breach's reach extends far beyond today's active force into veterans, retirees, reservists, National Guard members and their dependents.
- Breach window: October 2025 to July 16, 2026 — roughly nine months
- People notified: about 2.8 million living, nearly 300,000 deceased
- Data exposed: Social Security numbers plus at least one of name, date of birth, contact information, sex, race or military occupational specialty
- DMDC's total holdings: more than 60 million personnel records
The records were stored without encryption, according to both outlets' reporting, which is why the compromised server granted intruders direct access to readable Social Security numbers rather than scrambled data that would have required a separate decryption key. The roughly 3.1 million people notified represent a fraction of DMDC's total archive, which spans personnel, manpower, training and financial data reaching back to the early 1970s and covers active-duty troops, reservists, veterans, retirees, civilian DoD employees and their family members.
How the system was compromised
DMDC has operated since 1974 as the Pentagon's "central source for identifying, authenticating, authorizing and providing information on personnel during and after their affiliation" with the department, a role described in a Department of Defense system-of-records notice published in the Federal Register in March, which reissued the center's governing privacy notice under the new name Uniformed Services Human Resources Information System. The notice describes a system built to support manpower trend analysis, personnel readiness tracking and long-running statistical research — precisely the kind of comprehensive, decades-spanning dataset that makes DMDC attractive to attackers.
Federal civilian agencies operate under reporting rules set by the Cybersecurity and Infrastructure Security Agency requiring that incidents involving a confirmed breach of personally identifiable information be reported internally within one hour of identification by an agency's security team, under CISA's federal incident notification guidelines. That requirement governs how quickly an agency must alert CISA itself, a distinct obligation from notifying the individuals whose data was exposed — in this case, a gap that stretched from the July 16 discovery to the September 18 notification letters, roughly nine weeks.
Neither the Pentagon nor DMDC has said who was behind the intrusion. The department has said it currently has no indication the stolen data has been misused, but neither outlet reported how that assessment was reached, and a Pentagon spokesperson did not immediately answer questions from CNN about the identity of the intruders. The department has likewise not disclosed which specific file-sharing application or platform contained the flaw, how the vulnerability was initially introduced, or whether it has since audited other DMDC-connected systems for similar weaknesses.
Who is affected, and why it matters
Because DMDC records can include a service member's military occupational specialty alongside identifying details, cybersecurity researchers say the breach carries risks beyond ordinary identity theft. Justin Sherman, chief executive of the research firm Global Cyber Strategies, told Raw Story that combining the stolen fields with commercially available data could let an adversary profile individual service members in detail.
"If a foreign adversary was to get this kind of data trove, it could enable phishing, profiling, foreign intel approaches, and much more."
That concern is sharpened by the breach's duration. Nine months of undetected access gave intruders a long window to extract data gradually rather than in one traceable burst, complicating the Pentagon's efforts to determine exactly what was taken and by whom. Current service members whose occupational specialty was exposed could, in theory, be identifiable as holding particular roles — intelligence, cyber operations or other sensitive specialties — if that data were cross-referenced with other sources, according to the concerns raised by outside researchers.
What happens next
The Defense Department is offering affected individuals one year of credit monitoring and identity-restoration services through IDX, a private contractor, consistent with the standard response to large government data breaches. Affected individuals seeking broader guidance on recovering from identity theft can also consult the Federal Trade Commission's identitytheft.gov recovery resource, which outlines steps for placing fraud alerts and credit freezes.
Whether any law enforcement or intelligence agency has opened a formal investigation into the intrusion's origin remains unstated publicly. Lawmakers who oversee the Pentagon's cybersecurity posture have in the past demanded accountability after comparable breaches at defense and veterans' agencies, and the scale of this incident — covering millions of current, former and deceased personnel across every branch of the armed forces — makes continued congressional scrutiny likely in the weeks ahead. For now, the department's official position is that it has patched the vulnerability and restored the system, while it continues reviewing the full extent of what was exposed and to whom.
The notification letters give affected individuals a concrete, if time-limited, set of protections: one year of monitoring through IDX, after which recipients would need to pay for continued coverage or rely on free annual credit reports and their own vigilance. Social Security numbers themselves cannot be easily replaced, so the practical burden of watching for fraud tied to this breach will likely extend well beyond the year of paid monitoring the department is providing.
FTC opens investigation into OpenAI, Anthropic over AI agent safety risks

Micron reports record $54 billion quarter as AI memory boom accelerates
