Pentagon breach exposed sensitive data on nearly 3 million people
WASHINGTON, DC: A major data breach hit one of the Pentagon’s biggest personnel databases, exposing sensitive details for nearly 3 million current and former military members. Social Security numbers and specifics about the jobs people held were among the information exposed, according to a US defense official.
In total, the breach affected nearly 2.8 million living individuals, plus close to 300,000 deceased people. The leaked details went beyond basic personal data, with files including job assignments for military and civilian staff. The scope of the breach has raised concerns about the security risks associated with sensitive personnel information.
Pentagon personnel database was breached for months
"A Defense Manpower Data Center (DMDC) information system experienced unauthorized access of personally identifiable information by a small number of unauthorized users between October 2025 and July 2026. Upon discovery, DMDC immediately remediated the vulnerability," the official said
The Defense Manpower Data Center keeps track of more than 60 million personnel records, covering active-duty and reserve troops, civilian staff, contractors, retirees, veterans and military families.
It is one of the Pentagon’s main stores of personal information. A defense official said someone gained unauthorized access to this system from October 2025 until July of this year, when DMDC found and fixed the vulnerability.
So far, officials say they have not seen any evidence that someone used the exposed data for malicious purposes.
The department is offering those affected identity protection and credit monitoring. The breach came to light last week, after Military Times broke the story.
FBI jobs portal faced a separate breach
The news of the Pentagon breach came as the FBI sent a notice to employees on Friday outlining its response to a breach of its jobs portal, FBIJobs.gov.
A threat actor said it would publish data including FBI employees' names, home addresses, personal and work contact information, Social Security numbers, dates of birth and emergency contact information. Sources told ABC News that the bureau is operating as if every FBI employee's personal information was compromised.
But in a statement to the New York Times and 404 Media on Monday, the hacking group ShinyHunters claimed it would not release the data as it previously said it would.
"Since the very beginning of this event we have unequivocally and assiduously emphasised this is NOT extortion, this is NOT ransom, this is NOT financially motivated," the statement said.
"This was all a marketing campaign to protect our business and actively combat disinformation. If we made this statement normally then this much attention to our words and intentions would've never been this widespread."
The warning also told employees to stay silent with the media and to call 911 if they saw reporters trespassing on Bureau property.
Both breaches happened in the same week, putting cybersecurity concerns in the spotlight for the country's major law enforcement and defense agencies, which hold some of the government's most sensitive personnel data.