Oct 1 / Latest News

Pentagon’s DMDC Breach Exposes PII of 2.76 Million Individuals

A Pentagon‑run data system at the Defense Manpower Data Center (DMDC) suffered a breach exposing unencrypted PII belonging to 2.76 million living individuals and 294,000 deceased individuals, including service members, veterans, DoD employees, and their dependents.

DMDC, established in 1974, serves as the Pentagon’s central repository for personnel records, service status, and benefits eligibility across the U.S. Department of Defense. According to notification letters sent to affected individuals, DMDC discovered a vulnerability in its file‑sharing system on July 16, 2026, which had allowed unauthorized users to access files for months. Analysis determined that between October 2025 and the date of discovery, a small number of unauthorized users accessed a server containing unencrypted PII.

The exposed data varied by individual and included Social Security numbers, names, birth dates, contact information, race, sex, and military job specialties. DMDC stated it has no current evidence of misuse and has not disclosed who accessed the files or whether the data was copied. The agency said it is taking steps to assess and strengthen the cybersecurity posture of the affected Pentagon system.

To support impacted individuals, DMDC is offering 12 months of free credit monitoring through IDX, a breach‑response vendor contracted by the Department of Defense. The incident represents a significant exposure of sensitive military‑community data and follows closely after claims by the ShinyHunters extortion group that it compromised personal information belonging to FBI employees.