US News

EXPOSED: Pentagon Data Breach Leaks Social Security Numbers of 2.76 MILLION Military and Civilian Personnel

Gary FranchiSeptember 30, 2026232 views
Pentagon data breach exposes millions of Social Security numbers and personal details.
Pentagon data breach exposes millions of Social Security numbers and personal details. | Next News Editorial Illustration
Advertisement

A security failure at one of the Pentagon's central personnel repositories exposed the personal information of 2.76 million living U.S. military and civilian personnel and another 294,000 deceased individuals, a Defense Department official confirmed to Fox News. The compromised data, held at the Defense Manpower Data Center (DMDC), included Social Security numbers and details about the jobs those individuals held, according to an ABC News report citing a U.S. defense official.

Worse than the scope is the timeline. According to a Sept. 18 DMDC notification letter reviewed by Military Times, unauthorized users had access to a DMDC file-sharing server from October 2025 until July 16, 2026 — roughly nine months. The vulnerability was patched only after it was discovered, and affected individuals weren't notified by mail until September.

According to the notification letter, first reported by Military Times, the exposed files contained "unencrypted PII," including names, dates of birth, contact information, demographic data, and military occupational specialties. The department did not name the file-sharing product involved or describe the vulnerability.

"A Defense Manpower Data Center (DMDC) information system experienced unauthorized access of personally identifiable information by a small number of unauthorized users between October 2025 and July 2026. Upon discovery, DMDC immediately remediated the vulnerability," a defense official told ABC News.

The DMDC maintains personnel, manpower, training, and financial records for the department — more than 60 million files as of fiscal year 2024, covering active-duty and reserve troops, civilians, contractors, retirees, veterans, and military family members. The department told CNN that, at this time, there is no indication the accessed information has been misused.

It is not yet known who was behind the intrusion. According to SecurityWeek, no known cybercrime group has claimed credit for an attack on the DMDC. The letter states the affected system was restored after the patch was applied.

The breach lands alongside a second, separate incident. On Friday, the FBI sent employees a notice outlining its response to a compromise of the bureau's jobs portal, FBIJobs.gov, according to ABC News. Sources told ABC that a threat actor claimed it would publish FBI employees' names, home addresses, personal and work contact information, Social Security numbers, dates of birth, and emergency contacts — prompting the bureau to operate as if every employee's data had been taken. On Monday, a hacking group calling itself shinyhunters told the New York Times and 404 Media that it would not release the data as previously threatened.

Security experts have warned that the kind of data taken from the DMDC — particularly military occupational specialties matched to names and Social Security numbers — makes follow-on targeting easier. Phishing and impersonation attempts against personnel in sensitive roles become far more convincing when the attacker already knows a service member's job, unit history, and birth date. The DMDC letter says there are no current indications of misuse, which is not the same as saying the data isn't already circulating.

For now, the department's official posture is that notifications went out by mail to those whose information was in the affected files, and that the vulnerability has been closed. The identity of the intruders, the specific files touched, and how a nine-month unauthorized access window went undetected have not been publicly explained.

Our Take

Read that timeline again. October 2025 to July 2026. Nine months of outsiders walking through a Pentagon server holding the Social Security numbers and job records of millions of troops and civil servants — and the only reason we know is that a breach notification letter got leaked to a defense trade publication. The American people were not told. Congress was not told. The men and women who signed up to serve were not told until a form letter showed up in the mail this month.

This is the same federal government that spent years lecturing Americans about disinformation and demanding more power over what we say online. It cannot secure its own file-sharing server. This is the administrative state in its natural state: unaccountable, unencrypted, and unbothered — until it gets caught.

And ask yourself the questions nobody in the building wants asked. How does a vulnerability sit open for nine months inside the Defense Manpower Data Center without anyone noticing? Who had access to the system's monitoring logs, and why weren't they watching? Was this one contractor with a misconfigured server, or something worse? Meanwhile the FBI is handing out notices to its own employees telling them to assume their personal information is gone.

Two major federal breaches in a single news cycle is not bad luck. It is a pattern of an agency culture that treats data security as an afterthought and treats the public as an inconvenience to be managed when things go wrong.

So here is what every service member, veteran, and federal employee reading this should do today: freeze your credit, watch your accounts, and assume that anyone calling you with your own information already has it. And here is what Congress should do: subpoena the DMDC, demand the incident report, and make the people responsible for this nine-month window answer in public. This wasn't a hack that beat our defenses. This was a door left open, and no one has been held accountable yet. Will anyone be?

Advertisement
Advertisement
Gary Franchi
Gary Franchi

Chief White House Correspondent at Next News Network. Executive Producer and Lead Anchor.

Share this article:

Comments (7)

Leave a Comment

S
StarsAndStripesVerifiedjust now
What are they doing with all that defense budget if they can't protect sensitive information? This is a national security issue!
B
BlueCollarBillVerifiedjust now
Exactly, StarsAndStripes. It's about time they allocated funds for better cybersecurity instead of wasting it elsewhere.
U
USAFirstVerifiedjust now
Wow, 2.76 million. That's a lot of people affected. Who's responsible for this mess?
C
ConservativeVetVerifiedjust now
As a former service member, this hits close to home. I had my data compromised in the past, and it was a nightmare. We owe it to all who serve or have served to do better.
R
RedWhiteBlue4LifeVerifiedjust now
It's time for some major changes at the Pentagon if they're allowing this to happen. We've got to prioritize cybersecurity in this digital age. How many more breaches before something is done?
P
PatriotGuyVerifiedjust now
This is absolutely unacceptable! Our military personnel deserve better security for their personal info. Heads should roll for this breach!
L
LibertyLassVerifiedjust now
Completely agree, PatriotGuy. We need accountability and solutions, not excuses!