Listen to the article
A Pentagon breach that exposed sensitive personnel information for months is raising questions yet again about federal agencies’ ability to detect unauthorized access to their records.
Information about roughly 3 million people was potentially exposed from October 2025 to July 16, 2026, by a breach of a file-sharing system at the Defense Manpower Data Center, which maintains personnel information used across the military and other government agencies.
“Three million people may be the headline, but months of unauthorized access to highly sensitive data going undetected is the real warning,” said Nitay Milner, co-founder and CEO of data security company ORION Security.
Nextgov/FCW obtained a copy of the letter, which was signed by DMDC Director Katie Griffin. The accessed files contained unencrypted personal information, including Social Security numbers and, depending on the individual, names, birth dates, contact information and military occupational specialties.
“Upon discovery of the security vulnerability, DMDC immediately initiated privacy and cybersecurity incident response actions in accordance with Office of the Management and Budget and [Defense] Department guidelines and policies,” Griffin wrote. “We are taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system.”
DMDC patched the flaw and restored the system, according to the letter, and affected individuals are being offered a year of credit monitoring and identity-restoration services.
Military Times first reported the incident late last month, citing the same notice. A defense official later told CNN that the breach affected 2.76 million living people and another 294,000 deceased individuals.
The disclosure comes as the FBI responds to a separate breach claimed by prolific cybercrime group ShinyHunters, which likely exposed sensitive records of personnel involved in intelligence-gathering roles.
No public evidence has linked the intrusions, though both cases involve information that could help attackers identify government personnel and tailor attempts to deceive them through fraud schemes. Such data can also identify employees whose work is of particular interest to foreign intelligence services.
The breach is hardly the first to expose weaknesses in federal systems in recent years. In December 2024, Treasury disclosed that Chinese state-sponsored hackers accessed unclassified documents through a compromised remote-support service. Separately, the federal judiciary acknowledged attacks on its electronic case management system in August 2025, and the Congressional Budget Office confirmed unauthorized access to its systems that November.
AI systems are widely expected to accelerate cyberattacks, helping hackers find security weaknesses and use stolen personal information to make their targeting more precise and convincing.
Milner said detecting unauthorized activity requires agencies to understand who is gathering sensitive information, whether they are permitted to enter a given system and whether their behavior makes sense.
That scrutiny can matter even when an intrusion doesn’t immediately disrupt a system or draw attention. In the case of DMDC, the department’s notification described access spanning roughly nine months before the vulnerability was discovered.
Jeff Wichman, senior director of breach preparedness and response at Semperis, said agencies must plan for intrusions even when they have experienced security teams and established protections.
“The FBI and Pentagon have amazing responders, but these breaches are still happening and eventually everyone is hit,” he said. “True resilience depends on having a fully pressure-tested incident response plan detailing exactly which teams are responsible for what across the entire breach cycle, from initial discovery and containment to legal and regulatory reporting.”
He also warned that new government AI services, including the America.gov chatbot, could create more ways for attackers to reach sensitive information if those tools connect to agency systems. “More government agencies will fall victim to compromise,” he said. “Every piece of leaked data creates a domino effect.”
Read the full article here
5 Comments
Solid analysis. Will be watching this space.
Great insights on Defense. Thanks for sharing!
Interesting update on Pentagon, FBI personnel-data breaches raise questions. Looking forward to seeing how this develops.
Good point. Watching closely.
I’ve been following this closely. Good to see the latest updates.