Skip to content

Hackers stole millions of US military personnel records during months of data breach

The U.S. government is reportedly alerting millions of current and former U.S. military service members and personnel that their personal information was stolen during a months-long breach of Pentagon personnel records, the latest in a series of thefts involving federal worker data in recent months.

A data breach notification from the Defense Manpower Data Center (DMDC) shared on Reddit says that several unauthorized users exploited a security vulnerability in an unspecified file-sharing system over several months between October 2025 and mid-July 2026.

The breach exposed personally identifiable information, including Social Security numbers, along with a person’s name, date of birth, gender, race and other information about their military service. The notice says personnel records were not encrypted.

According cnn and Federal News NetworkA Pentagon official said the breach affects about 2.8 million living people and nearly 300,000 dead people.

The US military had 1.3 million active duty members in March.

The DMDC may not be well known to the general public, but it serves as one of the Department of Defense’s record-keeping units. DMDC maintains more than 60 million records on U.S. military and civilian personnel and their family members to help determine benefits and entitlements, such as health care and retirement. The unit also provides a critical service as the military’s “leading identity management provider,” linking active service members, employees and contractors with credentials such as smart cards and passwords. These are used to access Pentagon computer systems, buildings and bases.

“We ensure that the right people get access and the wrong people don’t – the security of identity information is paramount,” the DMDC website reads.

The Defense Department, which oversees the DMDC, said it has no indication that the information was misused, but did not say how it reached that conclusion. TechCrunch contacted a Pentagon spokesperson to ask if officials had any communications from the hackers, whose identities are unknown, but did not receive a response.

This is the latest major breach of federal workers’ personal information in recent months, following a recent breach. at the FBI in early September attributed to hacker group ShinyHunters. The hackers told TechCrunch that they had taken the personal information of most FBI agents and employees, including the applicants. The breach has been labeled a “counterintelligence disaster” amid risks that a foreign government could obtain and use the information to profile, attack or coerce federal workers into handing over sensitive information.

ShinyHunters hackers have said that They will not make public the data stolen from the FBI.

Both breaches involving the FBI and DMDC mirror similar thefts of government personnel records in the past. In 2015, a breach of the U.S. government’s human resources department, known as the Office of Personnel Management, was widely blamed on China. The breach allowed hackers to steal the private records of more than 22 million US government employees, many of whom had security clearances.

Did you receive a notice about this data breach? We want to hear from you. You can reach this reporter securely on Signal at zackwhittaker.1337, or reach him by email at zack.whittaker@techcrunch.com.

When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.

Leave a Reply

Your email address will not be published. Required fields are marked *