Defense Manpower Data Center Breach Exposes Unencrypted Military Records

2 min read
Source: Military Times
Defense Manpower Data Center Breach Exposes Unencrypted Military Records
Photo: Military Times
TL;DR

A vulnerability in a Defense Manpower Data Center file-sharing system allowed unauthorized access to unencrypted personal information, including Social Security numbers, for potentially four million military personnel between October 2025 and July 2026. The agency discovered the flaw in July and has since patched the system, offering affected individuals one year of credit monitoring services.

Key points

  • The Defense Manpower Data Center (DMDC) identified a security vulnerability in a file-sharing system on July 16, 2026.
  • Unauthorized users accessed unencrypted personally identifiable information (PII) on a server from October 2025 through July 16, 2026.
  • Exposed data included Social Security numbers and at least one other identifier, such as name, date of birth, or military occupational specialty.
  • Two sources familiar with the incident estimate that approximately four million Defense Department personnel may be affected by the breach.
  • The DMDC has patched the vulnerability and restored the system, with no current evidence that the exposed data was misused.
  • Affected individuals are being offered one year of credit monitoring and identity-restoration services through a private contractor, IDX.

Background

This incident follows a series of high-profile data breaches in 2026, including a cloud breach at Apollo Global Management and claims by the hacking group ShinyHunters regarding the FBI. The DMDC maintains over 60 million records for military and civilian personnel, making it a significant target for cyber threats.

Why it matters

The exposure of unencrypted Social Security numbers for a large portion of the military workforce poses a significant risk for identity theft and fraud. The breach highlights vulnerabilities in federal file-sharing systems and the importance of robust data protection measures for sensitive personnel records.

What to watch

The Defense Department and DMDC are expected to provide further details on the scope of the breach and the identity of the unauthorized users. Affected individuals should monitor their credit reports and watch for signs of identity theft, as the department has not confirmed whether the data was misused.

Share this article

Want the full story? Read the original reporting

Read on Military Times