A security breach at the Pentagon’s Defense Manpower Data Center exposed highly sensitive personal information belonging to more than three million people, with unauthorized users able to access vulnerable files for months before the problem was discovered.
The incident affected approximately 2.76 million living individuals and another 294,000 deceased people. The Defense Manpower Data Center, known as DMDC, maintains personnel information covering a broad range of people connected to the US military.
The exposed information varied between individuals but included Social Security numbers, names, dates of birth and contact information. Some files also contained demographic details and military personnel information, including occupational specialties. The affected files were not encrypted.
According to breach notifications, the problem originated with a security vulnerability in a DMDC file-sharing system. Investigators determined that a small number of unauthorized users had been accessing files on the affected server since October 2025.
DMDC discovered the vulnerability on July 16, 2026, meaning unauthorized access may have continued for approximately nine months. The agency says it immediately updated the file-sharing system to close the security flaw and restored the system after taking corrective action.
The Pentagon has not publicly identified the people responsible for accessing the files. Officials have also not explained whether the intrusion was part of an organized cyberattack, espionage operation, or another form of unauthorized activity. There is currently no evidence that the exposed personal information has been misused, according to defense officials.
The scale of the incident is particularly significant because DMDC serves as a central source of personnel information for the Defense Department. Its databases contain more than 60 million records associated with active-duty and reserve service members, civilian employees, contractors, retirees, veterans, and military family members.
The inclusion of occupational information adds another dimension to the breach. Beyond the identity theft risks created by exposed Social Security numbers and personal details, information describing military roles could potentially reveal more about an individual’s connection to the Defense Department.
People whose information was affected are being offered 12 months of credit monitoring and identity-restoration services through IDX.
DMDC has also initiated its privacy and cybersecurity incident response procedures and says it is taking additional steps to strengthen the security of the affected environment.
The final figure is lower than an earlier estimate that approximately four million Defense Department personnel could have been affected. The latest information from a US defense official places the confirmed scope at just over three million living and deceased individuals, while questions about who accessed the system and why remain unanswered.