BREACH WATCH BRIEF Critical 🤖 Breach

Pentagon personnel records breach exposes 2.76M SSNs and military data

Social Security numbers and other personal details of military personnel and their families were exposed in a months-long Pentagon breach.

SeverityCritical
Type🤖 Breach
ConfidenceHigh
ReportedOct 1, 2026
Government & Public Sector U.S. military personnel (active, reserve, retired) Civilian DoD employees and contractors Veterans and their families Estate administrators of deceased record holders Unknown Data Exfiltration

What happened

Cyber‑actors accessed an unencrypted file‑sharing server used by the Defense Manpower Data Center, extracting personal data for 2.76 million living individuals and 294 k deceased persons. The intrusion lasted from Oct 2025 to Jul 2026; no misuse has been confirmed.

Why it matters for trust and compliance

  • A breach at one organization is a third-party event for everyone who shares data with it. Check whether it reaches your vendors or your data.

Who is affected

U.S. military personnel (active, reserve, retired) Civilian DoD employees and contractors Veterans and their families Estate administrators of deceased record holders

Recommended actions

  1. Inventory DMDC data flows and verify encryption at rest and in transit.
  2. Validate retention and alerting of privileged‑access logs for at least 12 months.
  3. Request a detailed incident‑response disclosure from the Pentagon’s cyber‑security office.
  4. Advise affected individuals to use the offered credit‑monitoring service and consider a credit freeze.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.