
The Defense Manpower Data Center (DMDC), the Pentagon office that stores human-resources records for military and civilian personnel, has started sending breach notification letters to millions of people. According to the letters, “a small number of unauthorized users” exploited a vulnerability in DMDC’s file-sharing systems and had access to data between October 2025 and July 2026. Pentagon officials told Federal News Network the breach affects more than 3 million people: about 2.8 million living individuals and 294,000 deceased individuals.
What was taken varies by person, but can include Social Security numbers, names, dates of birth, contact information, sex, race and military personnel information. The Pentagon has not said who was behind the intrusion or which vulnerability was used, and did not immediately respond to BleepingComputer’s request for comment. DMDC holds more than 60 million military, civilian, contractor, family member, retiree and veteran records. This is the second large US government personnel breach in weeks, after the ShinyHunters theft from the FBI’s jobs site covered earlier.
How to check if you’re affected
Affected products and records are those held in DMDC’s personnel systems, so current and former service members, their families, and the families of deceased personnel are the likely recipients.
- Look for a DMDC notification letter. The Pentagon is offering 12 months of free credit monitoring through IDX, and you must enroll by August 19, 2027.
- Place a free fraud alert or credit freeze with the three credit bureaus, since Social Security numbers were exposed.
- Be suspicious of calls, texts or emails about “your DoD data breach” that ask for payment or a Social Security number. Scammers target breach victims; use only the contact details printed in your letter.
