The Pentagon is now notifying more than 3 million people that their personal information was stolen in a breach of its central personnel records system. If you are a current or former service member, a military family member, or a civilian Defense Department employee, a letter from the Defense Manpower Data Center (DMDC) may already be on its way to you.
Here is the short version: hackers had access to an unencrypted DMDC file-sharing server for roughly nine months, from October 2025 to mid-July 2026, and took personnel records that included Social Security numbers. The Pentagon says it has seen no signs of the data being misused yet, but experts warn that the stolen information is a lasting risk for identity theft and a potential goldmine for foreign intelligence services.
What happened in the Pentagon data breach
According to a breach notification letter from the DMDC reviewed by CNN and detailed reporting from TechCrunch, Federal News Network, and Fox News, the timeline looks like this:
- October 2025: Unauthorized access to a DMDC file-sharing system begins. The attackers got in by exploiting a security vulnerability in that system, which the Pentagon has not publicly identified, a pattern seen in recent zero-day attacks on enterprise systems.
- October 2025 to July 2026: The access continues undetected for roughly nine months, while a small number of unauthorized users access files on a server containing unencrypted personally identifiable information.
- July 16, 2026: DMDC discovers the vulnerability and remediates the issue, then begins a two-month internal assessment of the scope and impact.
- September 18, 2026: The Pentagon begins mailing breach notification letters to affected individuals.
- Late September to early October 2026: Affected service members and veterans start comparing notification letters online, and the story spreads nationally.
The DMDC is a central Department of Defense organization that tracks service histories, personnel assignments, ID credentials, and benefits eligibility across all military branches. It maintains more than 60 million records for military and civilian staff, veterans, and their families.
How many people are affected
A Defense Department official told CNN the breach affects approximately 2.76 million living individuals and 294,000 deceased individuals, for a combined total above 3 million. The affected group can include current and former service members, civilian DoD staff, military family members, and other people whose records sat in the affected system.
The nearly 300,000 deceased individuals in the count are a telling detail. It means the exposed dataset reached back decades of personnel history, not just recent records. For surviving family members, that creates its own exposure, because a deceased person’s Social Security number can still be used fraudulently in the wrong hands.
What is still unknown: who the attackers were, whether the files were copied rather than merely accessed, and whether the data has been used or sold. The Pentagon has offered no attribution and has not explained how it reached its conclusion that it has no indications of misuse.
What data was stolen
The exposed data varied from person to person but, according to the notification letters and reporting, included:
- Social Security numbers paired with names
- Dates of birth, sex, and race
- Contact information in some records
- Military occupational specialty (job specialty) and service details
All of it was stored unencrypted. That last point is the part security professionals keep returning to: a file-sharing server holding Social Security numbers should never have been running without encryption, and the intrusion went unnoticed for the better part of a year.
National security experts quoted by CNN add a second concern. The military job-specialty data, combined with identifiers like Social Security numbers and other datasets, could give foreign intelligence services a clearer read on who does what for the US military around the world. This is the same dynamic that made the 2015 Office of Personnel Management breach, which exposed records of more than 22 million government employees, so damaging.
What to do if you got the Pentagon breach letter
If you received a notification from the DMDC, treat this as a real identity-theft risk and act within the next few days, not weeks. SSNs and birth dates cannot be changed, and a Social Security number can only be changed in limited circumstances, so your defense is detection and lockdown.
1. Enroll in the free credit monitoring
DMDC is offering affected individuals 12 months of free credit monitoring through IDX, a breach-response company contracted by the department. Enroll using the instructions in your letter. Free monitoring for a year is better than nothing, but a year of monitoring does not fix a permanent SSN exposure, so do not stop here.
2. Pull your credit reports
Request your credit reports from all three major bureaus via AnnualCreditReport.com and look for accounts, inquiries, or addresses you do not recognize. This is the fastest way to spot identity theft already in progress. Federal breaches like this one tend to trigger a wave of new-account fraud months after the initial theft, so repeat this check periodically.
3. Freeze your credit
Place a credit freeze with Equifax, Experian, and TransUnion. It is free, it blocks anyone from opening new credit lines in your name, and you can temporarily lift it when you apply for credit yourself. A freeze is the single strongest protection against new-account fraud after an SSN exposure. If a lender cannot pull your credit, the application dies there.
4. Watch for targeted phishing
Expect spearphishing attempts that reference your service history, branch, rank, or assignment. Attackers with this dataset can write extremely convincing emails and calls. Verify any contact claiming to be from the DoD, the VA, or a defense contractor through a known channel before responding. Do not click links in messages that reference the breach or offer help with your letter. Locking down your accounts with two-factor authentication everywhere makes phishing attempts far less dangerous, even if one message slips through.
5. File your taxes early and watch the SSA
Stolen SSNs fuel tax-refund fraud and bogus benefit claims. Filing your tax return as early as you can each year beats a fraudster to the punch, and it is worth creating an account with the Social Security Administration and the IRS to monitor for activity you did not initiate.
How this breach compares
The DMDC breach is the second major federal personnel-data theft in a matter of weeks. Just recently, the ShinyHunters extortion group claimed it stole personal information of FBI employees. And the pattern echoes earlier incidents like the 2015 OPM breach, where a foreign government walked away with fingerprint data, SSNs, and background-investigation files of more than 22 million people.
The uncomfortable trend: attackers keep finding unencrypted or poorly guarded federal data stores, and the people affected keep getting one-year credit monitoring offers for lifetime-exposed Social Security numbers. If your information has been caught in more than one federal breach, a permanent credit freeze is the baseline, not the extra step. Breaches on this scale are exactly why stolen data keeps showing up for sale on the dark web, where full identity profiles from incidents like this one trade for years.
The bottom line
More than 3 million people are now dealing with the consequences of a breach that ran undetected for nine months on an unencrypted Pentagon server. The Pentagon says it sees no signs of misuse, but it cannot rule misuse out, and the data that was taken does not expire. If you got the letter, enroll in the monitoring, freeze your credit, pull your reports, file your taxes early, and treat every unexpected message about the breach as hostile until proven otherwise. Small businesses and organizations should treat this as a reminder too: the basics of protecting systems from hackers still matter more than any expensive security product.
Frequently asked questions
How do I know if I was affected by the Pentagon data breach?
The DMDC began mailing notification letters to affected individuals on September 18, 2026. If you are a current or former service member, civilian DoD employee, or military family member, watch for a letter from the Defense Manpower Data Center. The Pentagon has not published an online lookup tool.
What exactly was stolen in the DMDC breach?
Personnel records stored on an unencrypted file-sharing server, including Social Security numbers paired with names, dates of birth, sex, race, contact information, and military occupational specialty in some records.
Was my data encrypted?
No. The DMDC’s own notification letter states the attackers accessed files on a server containing unencrypted PII.
Is the free credit monitoring enough?
It helps, but 12 months of monitoring does not offset a permanently exposed Social Security number. Pair it with a credit freeze, regular credit report checks, and early tax filing for real protection.
Who hacked the Pentagon?
Unknown. The Pentagon has not attributed the intrusion and has not said whether the accessed files were copied. It says it currently has no indications of misuse but has not ruled out future misuse.
How long did the breach go undetected?
Roughly nine months, from October 2025 to July 16, 2026, when DMDC discovered the vulnerability. Notifications did not go out until about two months later, on September 18, 2026.
