Pentagon breach exposes records of 2.8 million people
A months-long breach of the Defense Manpower Data Center exposed unencrypted Social Security numbers of current and former US military personnel.
By Sam Reyes · Published · Updated · 5 min read

The US Department of Defense is notifying millions of current and former service members that their personal information was stolen from the Defense Manpower Data Center (DMDC), one of the Pentagon's main personnel record systems.
What happened
According to a breach notice shared online and reported by TechCrunch, several unauthorized users exploited a vulnerability in an unnamed file-sharing system between October 2025 and mid-July 2026. The notice says the records were not encrypted.
A defense official told ABC News the breach affects 2.76 million living people and about 294,000 who are deceased. The DMDC says it fixed the flaw as soon as it was discovered.
What data was exposed
- Full names and dates of birth
- Social Security numbers
- Sex and race
- Details of military service and the jobs people held
Why it matters
The DMDC holds more than 60 million records and acts as the military's identity provider, linking personnel to the smart cards and credentials used to enter bases and log in to Pentagon systems. Job details are especially sensitive: foreign intelligence services can use them to identify people in sensitive roles and target them with tailored phishing or recruitment approaches. Officials say there is no evidence yet that the data has been misused.
What affected people should do
- Freeze your credit with Equifax, Experian and TransUnion — it is free and blocks new accounts in your name.
- Watch for phishing emails and calls that mention your service history; attackers will use real details to sound convincing.
- Check your benefit and pay accounts for changes you did not make.
- Accept any identity protection offered in the official notice, but verify the letter came from the DoD before acting on it.


