Pentagon
Incident posture
Timeline
Summary
The Pentagon reported that unauthorized users accessed personally identifiable information from the Defense Manpower Data Center, including Social Security numbers and military employment details. The breach affected approximately 2.76 million living individuals and 294,000 deceased persons, out of a repository holding more than 60 million records. Officials said the vulnerability was discovered and patched, and there is currently no evidence that the exposed data has been misused. Affected individuals are being offered identity‑protection and credit‑monitoring services.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Between October 2025 and July 2026, unauthorized users gained access to records held by the Defense Manpower Data Center that contained personally identifiable information, including Social Security numbers and military employment details such as occupational specialty. The Defense Manpower Data Center is a repository maintained by the Department of Defense that stores more than sixty million personnel records covering active‑duty and reserve service members, civilian employees, contractors, retirees, veterans and military family members. According to a defense official cited by ABC News, the breach affected approximately 2.76 million living individuals and 294,000 deceased individuals. The Pentagon stated that the vulnerability was discovered in July 2026, subsequently patched, and that there is currently no evidence that the exposed information has been misused. An earlier breach notification indicated that the accessed files were unencrypted, exposing the same categories of data.
Following the discovery, the Department of Defense began offering identity‑protection and credit‑monitoring services to all individuals whose data was potentially compromised. The department emphasized that the vulnerability had been remediated and that ongoing monitoring would be conducted to detect any future unauthorized access. No specific misuse of the exposed Social Security numbers or military personnel information has been reported to date. The incident added to a series of recent data‑security concerns within federal agencies, prompting internal reviews of data‑encryption practices across Defense Department systems. Affected individuals were notified through official channels about the availability of the protective services.
The Pentagon breach occurred while the Federal Bureau of Investigation was investigating a separate possible breach involving its FBIJobs.gov employment application website, where an alleged threat actor claimed to have obtained names, addresses, contact information, Social Security numbers, dates of birth and emergency‑contact information of FBI employees. The FBI reported that it was operating under the assumption that employee personal information could have been compromised and had begun notifying affected employees accordingly. The hacking group ShinyHunters later told The New York Times and 404 Media that it would not release the allegedly obtained FBI data as previously threatened, describing the episode as a marketing campaign, a claim that ABC News said it had not independently verified. These developments highlight the broader environment of cyber threats facing multiple government agencies during the same period.
Sources
Sources available to members: 1 source.