A vulnerability in the file-sharing system of the Defense Manpower Data Center (DMDC) exposed the Social Security numbers and other personal information of more than 3 million individuals with ties to the U.S. military, according to a Pentagon official. This number includes 2.76 million living individuals and 294,000 deceased individuals. Unauthorized access to the data spanned from October 2025 until the DMDC discovered the vulnerability on July 16, 2026. An analysis conducted after the discovery revealed that the files were on a server containing unencrypted personally identifiable information; the DMDC then corrected the file-sharing system and restored it.
The DMDC, which falls under the Office of the Secretary of Defense, is responsible for centralizing data related to personnel, manpower, training, finances, and other areas on behalf of the U.S. Department of Defense. These data catalog the history of military personnel and their families for medical coverage, retirement funding, and other administrative needs. It has offices in Seaside, California, and Alexandria, Virginia. The DMDC presents itself as the central source for the Department of Defense responsible for identifying, authenticating, and providing information on personnel during and after their service within the department. It manages the records of more than 60 million military personnel, veterans, current and former civilian employees, contractors, and family members of military personnel, and oversees the identity verification of each holder of a Department of Defense identification card.
The official indicated that a "small number of unauthorized users" had accessed it. The notification letter sent to one of the affected individuals indicated that the recipient's Social Security number had been exposed, as well as at least one other identifier. These identifiers include the name, date of birth, contact information, gender, ethnicity, or information related to military personnel, such as professional specialty. The official specified that the type of data varied from person to person. The DMDC sent this letter on September 18, and two defense officials confirmed its authenticity. The incident was made public on September 24 in an article about this letter, which cited two individuals close to the case estimating that approximately 4 million Department of Defense personnel could be affected.
In its statement, the DMDC declared that it had "immediately implemented incident response measures related to privacy and cybersecurity" and would "take appropriate measures to assess and strengthen the cybersecurity of the DMDC system." The official indicated that there was no evidence that anyone's information had been misused. IDX, a company specializing in data breach management and recovery services engaged by the Department of Defense, will provide 12 months of credit monitoring and identity restoration services. A Pentagon official stated on September 3 that there was no indication of malicious activity or that this records issue had enabled a data breach. The Federal Trade Commission (FTC) specifies that any person can request a free credit freeze by contacting each of the three credit agencies. A credit freeze restricts access to a person's credit file and makes it more difficult to open new accounts in their name.
U.S. Military Personnel Data Breach Exposes Millions of Personal Records
AI-rewritten from original reportingHow it works
data-breachdefense-departmentssn-leakcybersecuritymilitary-datadmdc



