Pentagon tells 3 million military personnel their records were stolen in nine-month breach
The Defense Manpower Data Center says attackers sat in its file-sharing systems from October 2025 to July 2026 before anyone noticed.

Key points
- The Pentagon's Defense Manpower Data Center says attackers had access to personnel records from October 2025 until July 2026, roughly nine months before detection.
- More than 3 million people are affected, including about 2.8 million living individuals and 294,000 deceased, according to Pentagon officials.
- Stolen data varies by person but can include Social Security numbers, dates of birth, contact details, sex and race, along with military service information.
- The Pentagon is offering 12 months of free credit monitoring through IDX, with enrollment open until August 19, 2027.
- The notice lands days after the ShinyHunters extortion crew claimed to have stolen FBI personnel records via an Oracle PeopleSoft flaw.
The Pentagon is writing to millions of current and former U.S. Military personnel to tell them their records were stolen. The letters, first reported by BleepingComputer and now circulating online, come from the Defense Manpower Data Center, the office that holds the master personnel file for the U.S. Military.
The DMDC is the human-resources warehouse for the Department of Defense. It keeps more than 60 million records on service members, civilian staff, contractors, retirees and veterans, and those records are used to decide who gets pay, healthcare and benefits.
Someone broke into one of its file-sharing systems. The notice says "a small number of unauthorized users" had access to sensitive data from October 2025 through July 2026. Nine months of quiet access before detection.
The failure mode here is familiar. A file-transfer appliance gets a vulnerability, the patch cycle lags, and attackers live inside the data path for months. The Pentagon hasn't named the product or the specific flaw.
What was taken?
Stolen information varies person to person. According to the notification letters, it can include Social Security numbers, full names, dates of birth, contact details, sex, race and military personnel information such as rank and assignments. That's the exact mix used to open fraudulent credit lines and to run convincing impersonation scams against family members.
Pentagon officials told Federal News Network the breach touches more than 3 million people: around 2.8 million living, and 294,000 deceased. Records on dead service members matter because their Social Security numbers are routinely used in tax and benefits fraud.
What should affected people do?
If you get a letter, enroll in the free credit monitoring. The Pentagon's offering 12 months through IDX, and the enrollment window closes August 19, 2027. Beyond that, place a free credit freeze with the three major U.S. Credit bureaus. Treat any phone call or email that references your service record as suspicious until you verify it through an official channel. Scammers love fresh breach data because the details sound convincingly inside.
Is this connected to the FBI breach?
Not that anyone has said. The DMDC notice doesn't name a group. But it lands in the same week that the ShinyHunters extortion crew claimed to have stolen several terabytes of FBI personnel data by exploiting a zero-day, a previously unknown software flaw, in Oracle PeopleSoft, the HR platform widely used across the federal government. ShinyHunters told BleepingComputer the FBI breach wasn't financially motivated and the group doesn't intend to publish the data or extort the bureau.
We've covered ShinyHunters across 23 stories in the past 90 days, including a September 17 report on the group claiming 200,000-plus Florida driver records from a state DMV system. Those are unverified criminal claims, not confirmed hits, but the tempo tells you this crew's operating at industrial scale and favouring HR and identity systems. Whether the DMDC intrusion fits that pattern is the question investigators will have to answer.
| Detail | Figure |
|---|---|
| People affected | 3 million+ |
| Living individuals | ~2.8 million |
| Deceased individuals | 294,000 |
| Access window | Oct 2025 to Jul 2026 |
| Credit monitoring | 12 months via IDX |
| Enrollment deadline | Aug 19, 2027 |
Here's the operational read: if your file-transfer appliance can reach a database of 60 million identities, it isn't a file-transfer appliance. It's a crown-jewel system, and it deserves to be monitored like one.



