Defense Manpower Data Center Breach Exposes Unencrypted Military Records

A vulnerability in a Defense Manpower Data Center file-sharing system allowed unauthorized access to unencrypted personal information, including Social Security numbers, for potentially four million military personnel between October 2025 and July 2026. The agency discovered the flaw in July and has since patched the system, offering affected individuals one year of credit monitoring services.
Key points
- The Defense Manpower Data Center (DMDC) identified a security vulnerability in a file-sharing system on July 16, 2026.
- Unauthorized users accessed unencrypted personally identifiable information (PII) on a server from October 2025 through July 16, 2026.
- Exposed data included Social Security numbers and at least one other identifier, such as name, date of birth, or military occupational specialty.
- Two sources familiar with the incident estimate that approximately four million Defense Department personnel may be affected by the breach.
- The DMDC has patched the vulnerability and restored the system, with no current evidence that the exposed data was misused.
- Affected individuals are being offered one year of credit monitoring and identity-restoration services through a private contractor, IDX.
Background
This incident follows a series of high-profile data breaches in 2026, including a cloud breach at Apollo Global Management and claims by the hacking group ShinyHunters regarding the FBI. The DMDC maintains over 60 million records for military and civilian personnel, making it a significant target for cyber threats.
Why it matters
The exposure of unencrypted Social Security numbers for a large portion of the military workforce poses a significant risk for identity theft and fraud. The breach highlights vulnerabilities in federal file-sharing systems and the importance of robust data protection measures for sensitive personnel records.
What to watch
The Defense Department and DMDC are expected to provide further details on the scope of the breach and the identity of the unauthorized users. Affected individuals should monitor their credit reports and watch for signs of identity theft, as the department has not confirmed whether the data was misused.
Want the full story? Read the original reporting
Read on Military Times