DMDC DATA BREACH EXPOSES RECORDS OF 3 MILLION MILITARY-LINKED PEOPLE
The Defence Manpower Data Centre, a personnel-records unit of the US Department of War, has notified around three million current and former military-affiliated individuals that their personal information was stolen in a data breach. The DMDC said a security vulnerability in a file-sharing system allowed unauthorised users to access unencrypted records between October 2025 and mid-July 2026, before the flaw was discovered and patched on 16 July 2026. Stolen data included Social Security numbers, full names, dates of birth, sex, race, contact details and military service information such as occupational specialty. A Department of War official told CNN the breach affects 2.76 million living individuals and 294,000 deceased people, while a Pentagon spokesperson, Susan Gough, cited figures of about 2.8 million living people and close to 300,000 deceased in confirming the breach to other outlets. The DMDC said it has restored the affected system and is offering identity theft monitoring to those affected.
The DMDC, which sits within the Department of defence, maintains more than 60 million records covering military personnel, civilian employees, contractors and family members, and uses the data to help determine benefits such as healthcare and retirement. It also serves as what its website calls the military's "leading identity management provider", linking personnel to credentials such as smart cards and passwords used to access Pentagon systems, buildings and bases. Neither the identity nor the number of attackers has been confirmed, and officials have not disclosed which file-sharing system was targeted or detailed the nature of the vulnerability. Gough did not respond to questions about whether officials had received any communication from those responsible.
The Department of defence said it has no indication the stolen information has been misused, though it did not explain how it reached that assessment. The breach follows other recent incidents affecting US federal workers' data, including a breach at the FBI in September attributed to a group known as ShinyHunters. No further details on remediation steps or an ongoing investigation have been made public.