Pentagon notifies 2.8m after monthslong breach of military personnel records
The Pentagon has begun notifying more than two million current and former service members that a monthslong breach of a Defense Manpower Data Center system exposed Social Security numbers, names and occupational specialties — the second federal-agency hack in a month after the ShinyHunters FBI breach.

The Pentagon is informing more than two million current and former military members that their personnel records were stolen in a monthslong compromise of one of its networks, Ars Technica reported on Thursday.
According to a notification letter posted to Reddit, the records included Social Security numbers, names, addresses, sex, race and occupational specialty — the last a category that could help foreign intelligence agencies identify high-value military personnel. Hackers gained access to a system operated by the Defense Manpower Data Center, which collates Department of Defense personnel records, starting last October. The Pentagon says the breach compromised the records of 2.8 million living individuals.
It is the second major breach of a US federal agency in recent months. Last month, the ransomware group ShinyHunters claimed it hacked into FBI systems and stole records of thousands of current and former employees. Reuters reported the job titles in those records included roles related to investigating China or Russia.
The FBI confirmed the breach to The Register, saying it was aware of a “cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII)”, adding that the point of breach was still undetermined. ShinyHunters has said it has no plans to release the FBI data, while an FBI official this week called on the group’s members to turn themselves in.
Sources
- Ars Technica, “Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data” (1 October 2026)
- The Register, “ShinyHunters tells The Reg: We hacked the FBI to ‘protect our business’” (25 September 2026)
More on this topic: all Technology stories