Social Security numbers and military job details were among the records accessed, according to US defense officials
A Pentagon personnel system breach has reportedly exposed sensitive data on more than three million people, including military personnel and their families, several media outlets have reported, citing US defense officials. The disclosure follows a separate breach of the FBI’s jobs website.
The Defense Manpower Data Center (DMDC) system was reportedly accessed by a small number of unauthorized users between October 2025 and July 2026, affecting some 2.76 million living people and another 294,000 who are deceased, unidentified Pentagon officials have told CNN and ABC News.
According to them, the exposed files include Social Security numbers and other personal details, as well as information about military jobs and occupational specialties.
DMDC maintains more than 60 million records overall, including on active-duty and reserve troops, civilian employees, contractors, retirees, veterans, and military family members.
The leak was initially reported by the Military Times last week citing an internal breach notice received by one of the affected individuals. The publication said two unnamed defense officials had confirmed the authenticity of the letter.
According to the notice, DMDC said that a “security vulnerability” in a file-sharing system allowed unauthorized users to gain access to unencrypted personal information. The system was said to have been patched “immediately” after it was discovered – nearly nine months after the unauthorized access began.
The notice offered affected individuals a year of free credit monitoring services.
However, the Pentagon has not yet officially confirmed the breach, nor commented on who was behind the intrusion or what they did with the information they accessed.
Meanwhile, the FBI is dealing with an unrelated breach claim involving its recruitment website. Last week, the hacking group ShinyHunters claimed it had stolen personal data on nearly all FBI agents, their spouses, and job applicants.
The group said that the attack was “not financially motivated” and instead of a ransom, demanded that the FBI remove a cybersecurity advisory published in May that ShinyHunters says contains false allegations about them.
The FBI has said it is investigating and has notified employees, but has not yet established where the breach occurred or confirmed the scale of the theft.