The Defense Manpower Data Center, the Pentagon agency that keeps the personnel records behind military identification, benefits and eligibility, began mailing notification letters on 18 September 2026 about unauthorised access to a file-sharing system that ran from October 2025 until it was discovered and patched on 16 July 2026. Military Times reported the letters on 24 September. Defense officials later put the affected population at about 2.76 million living people and 294,000 deceased, a little over 3 million in all.
The files held unencrypted personal information: names, Social Security numbers, birth dates, contact details, sex, race and military occupational specialty and other personnel data. Those affected include current and former service members, civilian employees, contractors, retirees, veterans and family members. The department said a small number of unauthorised users had exploited a vulnerability in the file-sharing system, that it had no indication anyone’s information had been misused, and that it would not say who the users were or whether the access was targeted.
Unencrypted, In A File-Sharing System, For Nine Months
The department’s statement contains its own finding. Personnel records with Social Security numbers sat in a file-sharing system, unencrypted, reachable through a vulnerability for nine months. The corpus filed the file-transfer class of system at 23-0601 as the category that produced the MOVEit campaign three years earlier, and the sector-wide lesson was that these systems hold whatever passed through them. A defence personnel roster is among the more consequential things that could.
What A Roster Is
The record filed at 23-0808 set out why a workforce list is a target list by context. A list of 2.76 million living people connected to the U.S. military, with occupational specialty attached, is that list at national scale. It identifies who does what, where they can be reached, and for retirees and family members, who is connected to whom. The department declined to say whether the access was targeted, which is the question the population most needs answered and the one the notification letter cannot.
Two Months From Patch To Letter
The flaw was closed on 16 July. Letters were dated 18 September. The department said it acted in accordance with Office of Management and Budget and departmental guidelines, which is the standard answer and describes a process rather than a reason. One year of credit monitoring was offered. The record does not link this incident to a separate claim against an FBI recruitment site the same month, and the department did not either.
Compiled from the DMDC notification as reported, defence officials’ statements to reporters and contemporaneous coverage, listed below. The 3.07 million figure is officials’; an earlier 4 million figure was reporting of potential scope. The file-sharing product and the identity of the users were not disclosed. Graded high. Corrections: corrections@forensicpost.com.