AIO APEX

Pentagon records agency exposed unencrypted data on 3 million people for nine months

Federal News Network
Share:
Pentagon records agency exposed unencrypted data on 3 million people for nine months

The Defense Manpower Data Center (DMDC), the Pentagon office that maintains personnel records for more than 60 million current and former service members, civilian employees, contractors, and family members, has confirmed that a vulnerability in one of its file-sharing systems exposed unencrypted personal data on roughly 3 million people for nearly nine months before anyone noticed.

According to Pentagon officials, a small number of unauthorized users accessed the system between October 2025 and July 2026. The breach was discovered on July 16, 2026, at which point DMDC patched the vulnerability immediately and began formal privacy and cybersecurity incident-response procedures under Office of Management and Budget guidelines. The nearly year-long gap between initial access and discovery is itself the most troubling detail in the disclosure: a breach that runs undetected for nine months on a system holding Social Security numbers for active-duty personnel suggests monitoring gaps that go well beyond the single vulnerability DMDC says it has now closed.

The exposed data included full names, contact information, dates of birth, Social Security numbers, and military job specialties, all stored without encryption — a detail the Pentagon has not explained. Of the roughly 3 million affected individuals, 2.76 million are living and about 294,000 are deceased, meaning the exposure extends to historical personnel records as well as current ones. DMDC is arranging 12 months of complimentary credit monitoring through IDX for affected individuals, and officials say they have found no evidence so far that the exposed information has been misused.

That last point is the standard language issued after nearly every breach disclosure, and it means less than it sounds like: “no evidence of misuse” typically reflects the absence of detection capability as much as the absence of actual misuse, particularly for a breach that went unnoticed for nine months in the first place. Unencrypted Social Security numbers tied to military service records carry long-tail risk for identity theft and, for current personnel, a plausible foreign-intelligence targeting angle that the Pentagon has not addressed in its public statements.

The Pentagon has not named the unauthorized users, disclosed a motive, or said whether the incident is being treated as a criminal matter, an espionage concern, or ordinary credential compromise. As reported by Federal News Network, officials have likewise not explained why a system holding Social Security numbers for millions of military-affiliated individuals stored that data without encryption in the first place — a question that is likely to come up when the incident reaches congressional oversight committees.

Originally reported by Federal News Network. Read the original article for additional details.

View original source
Share: