Cybersecurity3 mins read

DoD Notifies Millions After Military Personnel Records Breach

Hackers stole personal information tied to current and former U.S. military personnel during a months-long breach involving Pentagon personnel records, according to TechCrunch.

What Happened

The Department of Defense notified millions of current and former U.S. military personnel that personal information was stolen in a months-long breach, TechCrunch reported. A Defense Manpower Data Center notice said several unauthorized users exploited a security vulnerability in an unspecified file-sharing system between October 2025 and mid-July 2026.

The hackers’ identities are not known. The breach is part of a broader run of recent incidents involving federal workers’ personal data.

What Information Was Exposed

The exposed data included personally identifiable information such as Social Security numbers, names, dates of birth, sex, race, and information about military service. The notice said the personnel records were unencrypted.

TechCrunch reported that CNN and Federal News Network cited a Pentagon official saying the breach affects about 2.8 million living people and close to 300,000 deceased people.

Why the DMDC Is Critical

The Defense Manpower Data Center maintains records for U.S. military and civilian staff and family members, helping determine benefits and entitlements such as healthcare and retirement. It also serves as the military’s leading identity management provider, linking service members, employees, and contractors to credentials used to access Pentagon systems, buildings, and bases.

That role makes the breach especially sensitive: identity and service records can have security implications beyond ordinary account exposure.

What to Watch Next

The Department of Defense said it had no indication the information was misused, but TechCrunch reported that officials did not explain how they reached that conclusion. Affected people should read any official breach notice carefully, preserve the documentation, and follow any protective steps offered by the government.

Key unresolved questions include how the vulnerability persisted for months, whether the stolen data has circulated, and whether additional notifications or technical details will follow.

Discover More

    The Danish flag flies outside a polling station at City Hall in Copenhagen, Denmark, on March 24, 2026.
    Denmark CPR Breach

    A Danish government database breach exposed records tied to about 8 million people.

    CybersecurityData breach