Defense Manpower Data Center
Incident posture
Linked entities
- Victim
- Defense Manpower Data Center
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A vulnerability in a Defense Manpower Data Center file-sharing system allowed unauthorized users to access a server containing unencrypted personally identifiable information, including Social Security numbers, contact details, demographic data, and military personnel information. The agency patched the vulnerability and restored the system after discovering the issue. Affected individuals were notified and offered a year of credit monitoring and identity-restoration services through IDX. The potential scope remains unclear, though people familiar with the incident said roughly four million Defense Department personnel may be affected.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
A vulnerability in a Defense Manpower Data Center file-sharing system allowed unauthorized users to access files containing unencrypted personally identifiable information, including Social Security numbers and military personnel data. The Defense Manpower Data Center, or DMDC, discovered the vulnerability on July 16, 2026. After the discovery, an analysis found that unauthorized users had accessed files on a server between October 2025 and July 16, 2026. The affected files contained unencrypted PII.
DMDC sent a breach notification letter on Sept. 18, 2026, to an individual whose information was contained in the affected files. The letter stated that the unauthorized users had accessed the recipient’s Social Security number along with at least one additional identifying detail. The additional information could have included a name, date of birth, contact information, sex, race, or military personnel information, including occupational specialty. The notice said the department had no indication that the individual’s information had been misused.
The potential scope of the breach remained unclear. Two people familiar with the incident told Military Times that approximately four million Defense Department personnel may be affected. DMDC did not provide a confirmed number of affected individuals in the available notification details. The Defense Department and DMDC did not immediately respond to questions about the number of people affected or the identity of those who accessed the files.
DMDC updated the file-sharing system to patch the vulnerability after discovering the problem and restored the system. The department offered affected individuals one year of credit monitoring and identity-restoration services through IDX, a private company contracted by the DoD. DMDC describes itself as the Defense Department’s central source for identifying, authenticating, authorizing and providing information on personnel during and after their affiliation with the department. Its website says it maintains more than 60 million DoD records involving military and civilian personnel, contractors, family members, retirees and veterans.
Sources
Sources available to members: 1 source.