Pentagon Data Breach Exposes Social Security Numbers, Military Job Details: Reports

A breach of a Pentagon personnel system exposed Social Security numbers and job details belonging to millions of people, with unauthorised users accessing sensitive information for months before the vulnerability was discovered and fixed in July, according to US media reports.
The breach affected 2.76 million living people and records of another 294,000 deceased individuals, a US defence official told ABC News. CNN separately reported that the exposed information included some service members’ “occupational specialty”, raising concerns about how the data could be used to identify and target military personnel.
The system belongs to the Defense Manpower Data Center (DMDC), one of the Pentagon’s main repositories for personnel information.
Access Continued From October to July
The defence official said a small number of unauthorised users accessed personally identifiable information between October 2025 and July 2026.
“Upon discovery, DMDC immediately remediated the vulnerability,” the official told ABC News.
The Health and Wellness Issue
25 Sep 2026 - Vol 05 | Issue 39
A notification letter sent to affected individuals and reviewed by CNN said the compromised data was not encrypted. It also confirmed that the problem had remained undetected until July.
DMDC maintains more than 60 million personnel records covering groups including active-duty and reserve troops, civilian employees, contractors, retirees, veterans and military family members. That figure represents its wider holdings, rather than the number affected by this breach.
Military Job Details Add to Security Concerns
The exposure extended beyond information commonly associated with identity theft.
In some cases, the accessed records identified the occupational specialties of military personnel, according to CNN. Such details could potentially be combined with other information to build profiles of individuals and their work.
Justin Sherman, CEO of advisory firm Global Cyber Strategies, told CNN that the data could support profiling, phishing or foreign intelligence approaches if obtained by an adversary.
Those are potential risks. Defence officials said they had found no indications that the compromised information had been misused.
The identity of those responsible remains unclear.
Credit Monitoring Offered to Victims
DMDC said it was assessing and strengthening the affected system’s cybersecurity and offering identity-protection resources, including a year of credit monitoring, to those affected.
The centre also serves as an access point for information on Department of Defense entitlements, benefits and medical readiness for military personnel, veterans and their families.
The Pentagon disclosure comes as the FBI separately notified employees about a breach involving its recruitment portal, FBIJobs.gov.
Sources told ABC News that an unidentified threat actor had threatened to publish employees’ names, home addresses, personal and work contact details, Social Security numbers, birth dates and emergency contacts.
The FBI was proceeding on the assumption that every employee’s personal information had been compromised, according to the report.
The hacking group ShinyHunters subsequently told The New York Times and 404 Media that it would not release the information as previously threatened. ABC News said it had not independently verified the group’s claims.
The reports did not establish a connection between the FBI incident and the Pentagon personnel-system breach.
With inputs from ANI
