A vulnerable file-sharing server at the Defense Manpower Data Center, the Pentagon office that maintains U.S. military personnel records, allowed unauthorized access to unencrypted personal data belonging to roughly 3 million people, the agency has disclosed. The exposure ran undetected for approximately nine months before it was found and patched.
Nine-Month Access Window at the Defense Manpower Data Center
DMDC, a U.S. Department of Defense office responsible for maintaining personnel records on active-duty service members, civilians, contractors, retirees, veterans, and their families, said unauthorized users were able to access files on the vulnerable server from October 2025 until the flaw was discovered and patched on July 16, 2026. That span works out to roughly nine months of unmonitored access before the agency detected the intrusion.
DMDC holds personnel data on approximately 60 million people in total. Of that population, the agency confirmed that 2.76 million living individuals and 294,000 deceased individuals had unencrypted personal information exposed during the access window, a combined total of about 3 million records.
Exposed Data Includes Social Security Numbers and Military Specialties
The categories of data exposed varied by individual but included Social Security numbers, full names, dates of birth, contact information, demographic details, and military occupational specialties, according to DMDC. Because the information was stored unencrypted on the compromised server, anyone who accessed the files during the nine-month window could have read it directly without needing to defeat any additional encryption layer.
DMDC has stated it has found no evidence that the exposed data was misused, and no individual or group has claimed responsibility for the intrusion. The agency has not disclosed how the unauthorized access was initially discovered or whether it identified a specific external actor behind the activity.
Two-Month Gap Between Discovery and Notification
DMDC patched and restored the vulnerable server on the same day the flaw was discovered, July 16, 2026, cutting off further unauthorized access. Notification letters to affected individuals, however, were not sent until September 18, 2026, roughly two months after the server was secured. The agency has not publicly detailed what occurred during that gap, such as forensic review, coordination with other Defense Department components, or letter preparation and mailing logistics.
Scope Spans Active-Duty, Retiree, and Family Records
Because DMDC’s personnel database covers multiple categories of DoD-affiliated individuals, the breach’s reach extends beyond current service members. Family members of military personnel, along with retirees, veterans, civilian DoD employees, and contractors, are among the population whose records DMDC maintains and whose data was potentially exposed if their file fell within the compromised access.
The combination of Social Security numbers, birth dates, and demographic detail exposed in the breach gives attackers the core building blocks needed for identity theft, fraudulent account creation, or targeted phishing against a population with ties to national defense infrastructure. Military occupational specialty data adds a targeting dimension not present in typical consumer breaches, potentially allowing an adversary to identify individuals by their technical role or unit function.
DMDC has said it launched a privacy and cybersecurity incident response following the discovery of the vulnerability. The notification letters sent beginning September 18 informed affected individuals of the exposure and the categories of data involved. No further public updates on remediation steps, such as credit monitoring offers or additional security controls on the file-sharing platform, have been disclosed alongside the initial notification.
The breach adds to a string of large-scale exposures affecting U.S. government-held personal data, and the nine-month dwell time combined with the two-month delay before notification is likely to draw scrutiny from oversight bodies given the sensitivity of the population affected and the volume of unencrypted Social Security numbers involved.