Security

Pentagon confirms DMDC breach exposed unencrypted data of 3.05 million for nine months

Unencrypted Social Security numbers and military records sat on a DMDC file-sharing server for nine months, and the Pentagon now says about 3.05 million people are affected.

T
By TechQuire Daily Staff TechQuire Daily Staff
September 29, 2026 / 7 min read

The Defense Manpower Data Center has spent decades as the quiet engine behind the Pentagon's personnel machine. The agency describes itself as the Defense Department's central source for identifying, authenticating, authorizing and providing information on personnel, and its website says it maintains more than 60 million Department of Defense records involving military and civilian personnel, contractors, family members, retirees and veterans. The center reported at least 60 million records as of fiscal year 2024. Almost everyone who has ever carried a military ID card, drawn a dependent's benefit or held a contractor badge has a record stored somewhere in that system.

That scale is what makes the breach disclosed in September 2026 so consequential. The Pentagon confirmed that unauthorized users reached a vulnerable computer server belonging to the DMDC beginning in October 2025, and that the intrusion went undetected for roughly nine months until the vulnerability was discovered on July 16, 2026. CNN reported on September 25 that the breach affects 2.76 million living individuals and 294,000 deceased individuals, numbers a Defense Department official provided to the network. Added together, the two groups come to about 3.05 million people.

The data was not encrypted. According to a breach notification letter dated September 18, 2026, and reviewed by multiple news organizations, the files on the affected server contained unencrypted personally identifiable information. For one recipient, that meant a Social Security number plus at least one additional piece of identifying information, such as a name, date of birth, contact information, sex, race, or military personnel information including occupational specialty. The file-sharing system was patched and restored on the day the vulnerability was discovered.

The department has said it has no indication that the information has been misused, and it is offering 12 months of credit monitoring and identity-restoration services through IDX, a private breach and recovery company contracted by the DoD. Affected individuals can enroll through a dedicated IDX website using a code from the notification, with a deadline of August 19, 2027. It remains unclear who was behind the access. No known cybercrime group has claimed responsibility, and officials have declined to say whether the affected people belong to any particular group.

Key Facts

Military Times reported on September 24 that a breach notification letter it reviewed described the full timeline. The letter, sent September 18 to an individual whose information was in the affected files, said DMDC discovered the vulnerability on July 16, 2026 in a file-sharing system. Analysis after discovery found that unauthorized users had accessed files on a server containing unencrypted personally identifiable information between October 2025 and July 16, 2026. Two defense officials confirmed the authenticity of the letter to Military Times. At that stage, two people familiar with the incident said approximately four million Defense Department personnel might be affected, so the potential scope was still unclear.

Federal News Network reported on September 28 that a Pentagon official described a small number of unauthorized users who had access for nearly a year, from October 2025 to July 2026. The same official said the exposed records covered the unencrypted names, contact information, dates of birth, Social Security numbers, military jobs and other details of nearly 2.8 million living individuals and 294,000 people who are deceased, with the specific type of data varying from person to person. The notice states that DMDC immediately initiated privacy and cybersecurity incident response actions in accordance with Office of Management and Budget and department guidelines and policies, and that the department is taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system.

The official declined to answer several questions, including who accessed the data, whether those affected belong to a particular group, whether the breach was intentional, and why personal information is stored on an unencrypted server. Those omissions have left outside researchers working largely from the notification letter. DMDC oversees identity verification for all DoD ID card holders and maintains the records of more than 60 million troops and veterans, current and former civilian employees, contractors and military family members.

SecurityWeek reported on September 29 that the DMDC notification letter, dated September 18 and shared online by a recipient, said unauthorized users had access to one of its file-sharing servers for roughly nine months. The letter does not name the affected file-sharing product and does not describe the vulnerability. Security Affairs, also reporting on September 29, noted that DMDC held at least 60 million records in fiscal year 2024 and that the 12 months of free credit monitoring through IDX carries an enrollment deadline of August 19, 2027. The affected department is referred to as the Department of War in some accounts of the letter, which states that at this time there are no indications of misuse of the accessed information.

Analysis

The most striking element of this incident is not the number of people in the notification letters but the combination of factors behind it: unencrypted Social Security numbers, on a file-sharing server, reachable by unauthorized users for nine months before anyone noticed. DMDC holds at least 60 million records, so 3.05 million affected individuals is a fraction of its holdings, but the affected slice is precisely the one that matters most for both identity crime and intelligence work. Social Security numbers are durable identifiers that cannot be reissued the way a password can.

Experts quoted by CNN said the data is a potential goldmine for foreign intelligence services looking to track US military personnel, or for cybercriminals looking to extort them. One piece of data accessed was, in some cases, the occupational specialty of service members. Combined with other datasets through identifiers such as Social Security numbers, that could give foreign adversaries a clearer read on who does what for the US military in various parts of the world. Justin Sherman, chief executive of the advisory firm Global Cyber Strategies, told CNN that a bad actor could pair the DMDC data with commercial datasets to target personnel based on earnings, debts, marriages, spending habits and browsing activities.

What this really means is that the damage assessment cannot be limited to credit monitoring offers. A Social Security number in a criminal database is a financial problem. A Social Security number linked to a military occupational specialty in the hands of a foreign service is a counterintelligence problem, and it does not expire when the 12 month monitoring window closes on August 19, 2027. The Pentagon says it has no indications of misuse, which describes what analysts have seen so far rather than what the data will be used for years from now.

The unanswered questions sharpen the concern. Officials will not say who accessed the files, whether the breach was intentional, or why personal information sat unencrypted on a file-sharing system at all. Those are not peripheral details. They determine whether this was an opportunistic scan that stumbled onto an open door or a targeted collection effort against the personnel records of the US military. Until the department answers them, the most reasonable assumption for anyone named in a notification letter is that their data should be treated as exposed, not merely possibly exposed.

Why It Matters

The breach touches nearly every corner of the defense workforce. DMDC records cover military and civilian personnel, contractors, family members, retirees and veterans, and the agency handles identity verification for every DoD ID card holder. That means the exposed group is not a single command or a single service branch, it is a cross section of the people who keep the department running, including 294,000 deceased individuals whose families may now face identity fraud built on records that should long ago have been sealed off from active use.

It also matters because of the nine month gap. From October 2025 to July 16, 2026, according to the notification letter, unauthorized users were inside a server holding unencrypted personal information, and the department did not detect it. The remediation itself appears to have been fast once discovered: the file-sharing system was patched immediately and restored. The failure was in detection, and in the decision to leave that class of data unencrypted on a system built for sharing.

Finally, the incident lands on a department that already stores at least 60 million personnel records and serves as the identity backbone for the entire force. Every future notification and every unanswered question about intent becomes part of the public record of how the Pentagon protects the people it tracks.

Next Up

Notification letters dated September 18 continue to reach affected individuals, who have until August 19, 2027 to enroll in the 12 months of credit monitoring and identity-restoration services provided through IDX. Military Times reported on September 24 that the potential scope was still being weighed, with sources putting the possible figure near four million Defense Department personnel, so the final count may shift as the department completes its analysis of the file-sharing server.

What remains open is the question of attribution and of intent. CNN reported on September 25 that it is unclear who was behind the breach, and no known cybercrime group has claimed it. Defense officials have said they will continue to assess and enhance the cybersecurity posture of the DMDC system, but they have not committed to explaining why unencrypted personal information was stored on a file-sharing server in the first place, which is the question likely to follow the department long after the credit monitoring period ends.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.