Pentagon admits nine-month breach exposed unencrypted military data

A nine-month data breach at the Defense Manpower Data Center (DMDC) exposed the unencrypted personal information, including Social Security numbers, of potentially four million current and former US military personnel. The intrusion began in October 2025 but was not discovered until July 2026. While the Pentagon states there is no evidence of data misuse, experts warn the exposed 'occupational specialty' data could aid foreign adversaries in targeting US troops, particularly amid ongoing conflicts in the Middle East.
Key points
- Unauthorized users accessed a vulnerable DMDC server from October 2025 to July 2026, a nine-month gap before detection.
- The breach exposed unencrypted data, including Social Security numbers and occupational specialties, for up to 4 million personnel.
- The Pentagon offers one year of credit monitoring to affected individuals but reports no signs of data misuse.
- Experts warn the data could enable foreign adversaries to profile, target, or extort military personnel.
- The DMDC maintains over 60 million records and serves as a central hub for military benefits and readiness data.
Background
This incident follows earlier reports in late September 2026 confirming the breach of the Defense Manpower Data Center. It occurs against a backdrop of heightened security concerns, including a federal appeals court ruling that upheld the Pentagon's designation of AI firm Anthropic as a national security threat, and rising casualties in the ongoing conflict with Iran, which has left 774 US service members wounded or killed.
Why it matters
The breach highlights significant vulnerabilities in the US military's digital infrastructure, potentially compromising the safety and privacy of millions of service members. The exposure of occupational specialties alongside personal identifiers creates a risk for targeted surveillance or cyberattacks, especially during active conflicts.
What to watch
The Pentagon is assessing and enhancing the cybersecurity posture of the DMDC system. Affected individuals have been offered credit monitoring services, but the identity of the intruders remains unknown.
Want the full story? Read the original reporting
Read on CNN