Desk live·
ForensicPost
Breaches/Public sector/File 26-0924

Pentagon Personnel Database Breach Exposed 3.07 Million People Through a File-Sharing Flaw

The Defense Manpower Data Center said unauthorised users had access from October 2025 to 16 July 2026. Letters went out on 18 September. The data was unencrypted: Social Security numbers, birth dates, race, occupational specialty, for service members, civilians, contractors, retirees and families.

Constructed geometry · not a chart of case data
JurisdictionUSAWashington, DCthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetDMDC personnel records
ActorUnattributed
D. Kennedy10 min readConfidence: high4 sources reviewed

The Defense Manpower Data Center, the Pentagon agency that keeps the personnel records behind military identification, benefits and eligibility, began mailing notification letters on 18 September 2026 about unauthorised access to a file-sharing system that ran from October 2025 until it was discovered and patched on 16 July 2026. Military Times reported the letters on 24 September. Defense officials later put the affected population at about 2.76 million living people and 294,000 deceased, a little over 3 million in all.

The files held unencrypted personal information: names, Social Security numbers, birth dates, contact details, sex, race and military occupational specialty and other personnel data. Those affected include current and former service members, civilian employees, contractors, retirees, veterans and family members. The department said a small number of unauthorised users had exploited a vulnerability in the file-sharing system, that it had no indication anyone’s information had been misused, and that it would not say who the users were or whether the access was targeted.

Unencrypted, In A File-Sharing System, For Nine Months

The department’s statement contains its own finding. Personnel records with Social Security numbers sat in a file-sharing system, unencrypted, reachable through a vulnerability for nine months. The corpus filed the file-transfer class of system at 23-0601 as the category that produced the MOVEit campaign three years earlier, and the sector-wide lesson was that these systems hold whatever passed through them. A defence personnel roster is among the more consequential things that could.

What A Roster Is

The record filed at 23-0808 set out why a workforce list is a target list by context. A list of 2.76 million living people connected to the U.S. military, with occupational specialty attached, is that list at national scale. It identifies who does what, where they can be reached, and for retirees and family members, who is connected to whom. The department declined to say whether the access was targeted, which is the question the population most needs answered and the one the notification letter cannot.

Two Months From Patch To Letter

The flaw was closed on 16 July. Letters were dated 18 September. The department said it acted in accordance with Office of Management and Budget and departmental guidelines, which is the standard answer and describes a process rather than a reason. One year of credit monitoring was offered. The record does not link this incident to a separate claim against an FBI recruitment site the same month, and the department did not either.

How we reported this

Compiled from the DMDC notification as reported, defence officials’ statements to reporters and contemporaneous coverage, listed below. The 3.07 million figure is officials’; an earlier 4 million figure was reporting of potential scope. The file-sharing product and the identity of the users were not disclosed. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Military personnel data exposed in breach, agency warnsMilitary Times
  2. More than 3 million people affected by military data breachFederal News Network
  3. Breach at Pentagon personnel database exposed data of millionsStars and Stripes
  4. What to Know About the Pentagon Breach Affecting MillionsTime
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary