Pentagon's DMDC Breached: Data of 3 Million Military Personnel Exposed
The **Pentagon's Defense Manpower Data Center (DMDC)** has confirmed a data breach impacting over 3 million military service members, both active and deceased. Hackers exploited a vulnerability in the DMDC's file-sharing systems, gaining unauthorized access to sensitive personally identifiable information (PII) over several months.
The **Defense Manpower Data Center (DMDC)**, a critical operational support center for the **U.S. Department of Defense (DoD)**, is notifying millions of military personnel about a significant data breach. The incident, which occurred between October 2025 and July 2026, saw unauthorized users access sensitive data by exploiting a vulnerability in the **DMDC's** file-sharing systems.
### Scope of the Breach
The breach affects more than 3 million individuals. This includes approximately 2.8 million living individuals and 294,000 deceased individuals whose records are maintained by the **DMDC**. The stolen data is extensive and varies by person, encompassing:
* Social Security numbers (SSNs)
* Names
* Dates of birth
* Contact information
* Sex
* Race
* Military personnel information
### DMDC's Response and Mitigation Efforts
Upon discovering the security vulnerability, the **DMDC** initiated immediate privacy and cybersecurity incident response actions. These actions align with **Office of Management and Budget** and **Department** guidelines and policies. The **DMDC** has stated it is taking appropriate measures to assess and enhance the cybersecurity posture of its systems.
As a compensatory measure, the **Pentagon** is offering affected individuals 12 months of free credit monitoring services through the **IDX** data breach and recovery service provider. Individuals must enroll by August 19, 2027, to utilize this service.
### The DMDC's Vital Role
Established in 1974, the **DMDC** is responsible for storing over 60 million records pertaining to military members, civilians, contractors, family members, retirees, and veterans. This vast database is crucial for authorizing benefits and entitlements, as well as managing training, financial, and other data for the **DoD**. The center also oversees **DoD** personnel programs and conducts research and analysis under the direction of the **Office of the Secretary of Defense (OUSD)**.
Its official overview highlights its broad impact, stating, "The services and access to data we provide support so many vital government entities, including the legislative branch, human services, national defense, labor, healthcare, finance, veterans affairs, research, and more."
### Broader Context of Government Breaches
This incident follows another high-profile breach claimed by the **ShinyHunters** extortion gang, which targeted the **FBI's FBIjobs.gov** site. In that attack, **ShinyHunters** reportedly exploited an **Oracle PeopleSoft** zero-day vulnerability to steal several terabytes of data. This data allegedly included names, Social Security numbers, home addresses, and assignments belonging to "almost ALL **FBI** Agents," including members of the **FBI Remote Operations Unit**, a team involved in hacking operations. Notably, **ShinyHunters** stated that the **FBI** breach was not financially motivated and that the group had no intention of publishing the stolen data or extorting the bureau.
