Millions of Military Personnel Victims of Data Breach at Pentagon’s Human Resources Management System
A massive data breach has affected over 3 million military service members, with hackers stealing sensitive information from the Pentagon’s human resources management system in October 2025. The breach was discovered after a vulnerability in the file-sharing systems was exploited by unauthorized users between October 2025 and July 2026.
The stolen data varies by person but includes personally identifiable information (PII), such as Social Security numbers, names, dates of birth, contact information, sex, race, and military personnel details. This sensitive information can be used for identity theft, financial scams, or other malicious activities. The breach affects both living individuals and deceased individuals, with nearly 2.8 million living people affected.
The Pentagon’s Defense Manpower Data Center (DMDC) is responsible for storing the records of over 60 million military personnel, civilians, contractors, family members, retirees, and veterans. This data is used to authorize benefits and entitlements, as well as training, financial, and other data for the U.S. Department of Defense (DoD). The breach highlights the importance of robust cybersecurity measures in protecting sensitive information.
The DMDC has notified affected individuals through data breach notification letters shared online by affected personnel. These letters inform them that “a small number of unauthorized users” accessed their sensitive data after exploiting a vulnerability in the file-sharing systems. The DMDC has also initiated incident response actions and is assessing its cybersecurity posture to prevent similar breaches in the future.
The Pentagon is offering 12 months of free credit monitoring services through IDX, a data breach and recovery service provider. Affected individuals must enroll by August 19, 2027, to take advantage of this offer. The DMDC has assured that it is taking all necessary steps to protect its systems and prevent similar breaches.
This incident follows another massive data breach claimed by the ShinyHunters extortion gang, who breached the FBI’s FBIjobs.gov site using an Oracle PeopleSoft zero-day. While ShinyHunters claimed not to have financially motivated intentions, this recent breach highlights the growing threat of sensitive information being compromised.
To mitigate the risk of data breaches, it is essential for individuals and organizations to prioritize robust cybersecurity measures, including regular software updates, secure authentication protocols, and incident response planning. Affected individuals should take advantage of the offered credit monitoring services and remain vigilant about their personal data security.
Source: Bleeping Computer — 2026-10-01