Pentagon HR breach exposed unencrypted personal data of up to 4 million US military personnel
Unauthorised users accessed a Defence Manpower Data Center file-sharing server from October 2025, exposing unencrypted personal data of potentially 4 million US military personnel, according to Military Times and CNN.

Unauthorised users accessed a file-sharing server belonging to the Defence Manpower Data Center (DMDC) from October 2025, exposing unencrypted personal data of potentially four million US military personnel, according to reports by Military Times and CNN.
The DMDC discovered and remediated the vulnerability on July 16, 2026. In a breach-notification letter sent to victims on September 18 — reviewed by both outlets — the centre said the exposed files contained Social Security numbers, names, dates of birth, contact details, sex, race and military occupational specialty. The letter’s authenticity was confirmed by two defence officials.
The exact number affected has not been confirmed by the Pentagon, but two people familiar with the incident told Military Times that approximately four million Defense Department personnel may have been affected.
The Pentagon said it currently “does not have any indications of misuse” of the data. It is unclear who was behind the breach; a Pentagon spokesperson did not respond to CNN’s questions, including who the culprit was.
National security experts warned the stolen data could be a counterintelligence goldmine. Justin Sherman, CEO of advisory firm Global Cyber Strategies, told CNN that if a foreign adversary obtained the trove it could enable “phishing, profiling, foreign intel approaches, and much more”. The DMDC — the Pentagon’s central HR system — maintained at least 60 million records as of fiscal 2024, according to CNN.
Sources
More on this topic: all Technology stories
