Pentagon Breach Left Social Security Numbers of Nearly 3 Million Troops Exposed for Months
Unauthorized users spent roughly nine months inside a Pentagon file-sharing server holding personnel records, exposing data tied to about 3 million current and former service members.

Someone had access to Pentagon personnel files for roughly nine months before anyone noticed.
A Pentagon official confirmed to TIME that about 2.76 million living people and about 294,000 deceased people were affected by a breach at the Defense Manpower Data Center. That puts the total at more than 3 million records.
DMDC is not a side office. It is the Defense Department's central store for personnel, manpower, training, and related records, the data that follows service members through and after their careers.
Nine months of access
Military Times first reported the incident from a breach notification letter dated Sept. 18. According to that letter, DMDC discovered a security vulnerability in its file-sharing system on July 16. Unauthorized users had been accessing files on a server from October 2025 until that discovery.
What was exposed varies by file. Depending on the record, it can include names, dates of birth, contact information, Social Security numbers, and job details. For troops, veterans, and families of the deceased, an SSN paired with a date of birth is exactly what identity thieves need to open accounts or file fraudulent claims.
The notification also arrived two months after discovery, and nearly a year after the intrusion began.
What DMDC says it has done
DMDC says it has updated the file-sharing system and that there was no indication of misuse for the recipient of the notification. It is offering a year of credit monitoring and identity-restoration services through IDX.
The department has not publicly named who was behind the access, and there is no public evidence so far that the stolen Social Security numbers have been used. File-sharing platforms have been a favorite entry point for data theft crews in recent years, and enterprise software holes keep turning up in government and corporate systems alike.
One year of monitoring is a short window for data that does not expire. A Social Security number stays the same for life, and the people whose records sat on that server for nine months will be carrying that exposure long after the IDX coverage ends.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free