Pentagon personnel records breach exposes 2.76M SSNs and military data
Social Security numbers and other personal details of military personnel and their families were exposed in a months-long Pentagon breach.
ADTP Breach Watch· October 1, 2026· Malwarebytes Labs
SeverityCritical
Type🤖 Breach
ConfidenceHigh
ReportedOct 1, 2026
Government & Public SectorU.S. military personnel (active, reserve, retired)Civilian DoD employees and contractorsVeterans and their familiesEstate administrators of deceased record holdersUnknownData Exfiltration
What happened
Cyber‑actors accessed an unencrypted file‑sharing server used by the Defense Manpower Data Center, extracting personal data for 2.76 million living individuals and 294 k deceased persons. The intrusion lasted from Oct 2025 to Jul 2026; no misuse has been confirmed.
Why it matters for trust and compliance
A breach at one organization is a third-party event for everyone who shares data with it. Check whether it reaches your vendors or your data.
Who is affected
U.S. military personnel (active, reserve, retired)Civilian DoD employees and contractorsVeterans and their familiesEstate administrators of deceased record holders
Recommended actions
Inventory DMDC data flows and verify encryption at rest and in transit.
Validate retention and alerting of privileged‑access logs for at least 12 months.
Request a detailed incident‑response disclosure from the Pentagon’s cyber‑security office.
Advise affected individuals to use the offered credit‑monitoring service and consider a credit freeze.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.