Hackers stole Pentagon personnel records of over 3 million people

The Pentagon’s human resources management system has been breached, resulting in the theft of sensitive personnel records for over 3 million people. The stolen data includes personally identifiable information (PII) such as Social Security numbers, names, dates of birth, contact information, and military personnel details.

The breach occurred between October 2025 and July 2026, when a vulnerability in the Pentagon’s file-sharing systems was exploited by unauthorized users. The Defense Manpower Data Center (DMDC), which operates the system, is notifying affected individuals through data breach notification letters shared online by those who have received them.

According to the DMDC, the stolen data varies by person and includes sensitive information such as Social Security numbers, names, dates of birth, contact information, sex, race, and military personnel details. The Pentagon has confirmed that the breach affects more than 3 million people, including nearly 2.8 million living individuals and 294,000 “deceased individuals.”

The DMDC has stated that upon discovery of the security vulnerability, they immediately initiated incident response actions in accordance with Office of Management and Budget and Department guidelines and policies. The Pentagon is also offering 12 months of free credit monitoring services through the IDX data breach and recovery service provider.

This breach raises concerns about the security of sensitive government data. The DMDC is responsible for storing more than 60 million military, civilian, contractor, family member, retiree, and veteran records used to authorize benefits and entitlements, as well as training, financial, and other data for the U.S. Department of Defense (DoD). This incident highlights the need for robust cybersecurity measures to protect sensitive government information.

It’s worth noting that this breach follows another high-profile data breach claimed by the ShinyHunters extortion gang, who breached the FBI’s FBIjobs.gov site using an Oracle PeopleSoft zero-day. While ShinyHunters claims the breach was not financially motivated and they don’t intend to publish or extort the stolen data, it raises questions about the vulnerability of sensitive government information.

Affected individuals are advised to enroll in the free credit monitoring services offered by the Pentagon to protect their financial information. The DMDC’s incident response actions will also aim to assess and enhance the cybersecurity posture of its system.

In practical terms, this breach serves as a reminder that even with robust security measures in place, vulnerabilities can still be exploited. It’s essential for individuals and organizations to stay vigilant and regularly review their security protocols to prevent similar breaches from occurring in the future.


Source: Bleeping Computer — 2026-10-01