Zero Day Room
Live
Incidents

Pentagon breach exposes 2.76 million SSNs in personnel data

The Pentagon has confirmed a months-long breach of its Defense Manpower Data Center, exposing unencrypted Social Security numbers and personal details.

The Pentagon has confirmed a months-long breach of its Defense Manpower Data Center, exposing unencrypted Social Security...

The Pentagon confirmed a prolonged breach exposing the Social Security numbers and personal data of 2.76 million living individuals and 294,000 deceased people. The incident occurred within the Defense Manpower Data Center system between October 2025 and July 2026, compromising one of the military's primary personnel record repositories.

This massive breach highlights critical vulnerabilities in federal identity management systems. The DMDC maintains over 60 million records for military, civilian, contractor, family member, retiree, and veteran personnel. Officials stated the breach was executed by "a small number of unauthorized users" exploiting a vulnerability in Pentagon file-sharing systems. Over 3 million affected military service members and personnel have been notified.

Sensitive data exposed without encryption

The stolen data was unencrypted during the breach. It included highly sensitive personal information beyond Social Security numbers.

This combination of data creates significant risks for identity theft and targeted phishing campaigns. The exposure of job details alongside personal identifiers compounds the security threat for active-duty and reserve personnel.

Pentagon offers credit monitoring to affected personnel

In response, the Defense Manpower Data Center is providing 12 months of free credit monitoring through IDX. This service is being offered to all individuals impacted by the breach, which includes both living and deceased personnel whose records were compromised.

Enrollment must be completed by August 19, 2027. Employees have begun receiving notification letters with instructions for enrolling in the protection program. Internal guidance advised affected personnel to maintain situational awareness regarding their financial accounts and to avoid suspicious phone calls or communications.

ShinyHunters linked to separate FBI breach

This Pentagon breach follows a separate incident involving the ShinyHunters hacking group. That group claimed to have stolen data from the FBI's FBIjobs.gov recruitment portal using an Oracle PeopleSoft zero-day vulnerability. ShinyHunters stated their FBI breach was not financially motivated and they did not intend to publish or extort the stolen data.

A sample of data affecting 5,000 supposed FBI agents was sent to a media portal, containing names, home addresses, phone numbers, and information on agents' spouses. The hackers claimed this access was gained in retaliation for false allegations about their operations. The Pentagon has stated it has no evidence confirming the identity of the hackers behind its breach or any communication from them, and has not verified ShinyHunters' claims regarding the FBI incident.

This latest breach represents another significant compromise of strategically important U.S. Agency data. It echoes the scale of the 2015 Office of Personnel Management breach, which was attributed to China and compromised over 22 million government employees' records. Affected individuals must enroll in the offered credit monitoring by August 19, 2027.

Related coverage

More from Incidents