A Pentagon data breach exposed personal information connected to 2.76 million living people and 294,000 deceased people, the Defense Department says. The records included sensitive identifying details, but officials have not publicly identified who accessed them or established whether the information was misused.
The breach involved a file-sharing system at the Defense Manpower Data Center, or DMDC, which maintains records for a population broader than active-duty troops. A vulnerability allowed unauthorized users to access files between October 2025 and July 16, 2026, according to the center’s notice and Pentagon officials.
The department says it patched the vulnerability and has no evidence that the information has been misused. It has offered affected people one year of credit monitoring and identity-restoration services. Neither the absence of known misuse nor that offer answers why the information was accessible for months.
What information was exposed?
Reported exposed fields included names, contact information, dates of birth, Social Security numbers and military occupational information. The data varied by person: the reports do not establish that every affected record contained every listed detail. A breach notice reviewed by Military Times described the exposed personally identifiable information as unencrypted.
The Pentagon’s affected-person count identifies living and deceased people separately. It does not say how many of the living were current service members, veterans, relatives, civilian employees, contractors or members of other groups. A Pentagon official declined to tell Federal News Network whether the affected people belonged to a particular group.
DMDC brings together personnel, training, financial and other information used for Defense Department administration, including health care and retirement funding. Its records cover people beyond those currently serving. The center maintains more than 60 million records overall, according to its website as reported by Federal News Network and Military Times; that figure is not the number of records exposed in this breach.
The distinction matters for people trying to understand their own risk. Knowing that a field appeared somewhere in the exposed files does not establish that it appeared in any particular person’s record. The reporting has not provided a public breakdown of which categories of information were exposed for which affected groups.
How long did the Pentagon take to find the vulnerability?
Unauthorized users accessed files during a period stretching from October 2025 to July 16, 2026, according to the breach notice and Pentagon officials. DMDC discovered the vulnerability on July 16 and patched it, the department says. CBS News reported on the months-long discovery period.
Military Times reviewed a notification letter dated Sept. 18 and first reported the breach Thursday. At that point, the outlet attributed an estimate of approximately 4 million potentially affected Defense Department personnel to two people familiar with the incident. The Pentagon’s later figures — 2.76 million living people and 294,000 deceased people — are more specific. The earlier estimate should not be treated as a confirmed total.
A Pentagon official said affected individuals were notified by mail. The available reporting does not establish precisely when each notice arrived or whether each recipient was told every specific field exposed in their record.
Federal News Network reported that a Pentagon official declined to answer who accessed the files, whether the access was intentional or why the information was stored on an unencrypted server. Those are questions about the department’s safeguards, not evidence that any particular person used the data for fraud.
Free newsletter
Get the morning briefing
Start each day with the stories that matter and why — a short, free email from our newsroom.
What protection has the department offered?
DMDC’s notice offered affected individuals 12 months of credit monitoring and identity-restoration services through IDX, a company contracted by the department. The notice also said the center had begun a privacy and cybersecurity response and was assessing and enhancing the system’s security.
Credit monitoring addresses one potential consequence of exposed identifying information; it does not explain who obtained the files or what they did with them. The Pentagon says it has no evidence of misuse. That is a statement about what officials have found, not confirmation that misuse could not occur.
TIME reported that security experts warn large collections of personal information can make phishing attempts easier. The reporting does not establish that people affected by this breach have experienced phishing, identity theft or financial losses because of it.
People can request free credit freezes from the three major credit bureaus, according to Federal Trade Commission information reported by TIME. TIME also reported that active-duty personnel and National Guard members can access free electronic credit monitoring. Those options do not change the department’s responsibility to explain the exposure and its response.
Does Hegseth’s officer overhaul explain the breach?
Defense Secretary Pete Hegseth has proposed reducing senior military positions as part of a reorganization. In written testimony dated June 12, 2025, he set targets of at least 20% fewer active-component four-star positions and National Guard general officers, and at least 10% fewer general and flag officers alongside a realignment of the military’s command structure. He presented the changes as a way to remove unnecessary bureaucratic layers and support military effectiveness.
Those figures are targets, not evidence that the cuts were completed. The available reporting does not show that the overhaul changed staffing or cybersecurity oversight at DMDC, or that it contributed to the file-sharing vulnerability. The breach cannot be explained by pointing to the proposed officer reductions without evidence connecting them.
Hegseth nevertheless leads the department responsible for protecting the records and accounting for its response. The immediate oversight question is what happened to this system: why unencrypted personal information was reachable, why the vulnerability was not discovered sooner and what safeguards will keep it from recurring.
For the millions of living people in the Pentagon’s count, the department has offered a year of services while leaving those questions publicly unanswered. DMDC says it is assessing and enhancing security; officials have yet to explain who accessed the files or why the exposed information was stored unencrypted.
Comments
Comments are written by readers. They are not reporting or opinion from The Wells Post.
Share your view on this story. Criticise ideas and public records, not other readers.
Most comments appear right away; some wait for a moderator first.
Community guidelines
More in our terms and privacy policy.
No comments yet. Start the conversation.