The Defense Department's DMDC suffered a months-long breach that reportedly exposed personal data for roughly 2.76 million living and 294,000 deceased individuals, including Social Security numbers and job details. A DMDC notification said a file-sharing vulnerability discovered on July 16 allowed unauthorized access between October and discovery. DMDC is offering one year of credit monitoring through IDX, and the FBI is separately investigating a possible ShinyHunters attack on its jobs site. Experts warn such aggregated data raises the risk of phishing, identity theft and national-security exposure.
Pentagon Data Breach Exposes Millions: What Happened, Who’s Affected, and What To Do

A months-long intrusion into the Defense Department's human-resources database at the Defense Manpower Data Center (DMDC) reportedly exposed personal information for millions of people connected to the military, including Social Security numbers and employment details. Unidentified Pentagon officials told multiple outlets that roughly 2.76 million living and about 294,000 deceased individuals were affected.
What happened
According to a DMDC breach-notification letter reviewed by media, the center discovered on July 16 that a vulnerability in a file-sharing system allowed unauthorized users to access files on a server. The notice says that access occurred between October (the letter did not specify a year) and the time of discovery. The specific files and the identity of the intruders remain under investigation.
Who Is Impacted
The DMDC maintains personnel, manpower, training, financial and other records used for Defense Department needs such as health care and retirement. Based on FY2024 figures, the DMDC's database includes records for more than 60 million people: active-duty service members, civilians, contractors, family members, retirees and veterans. The breach-notification letter indicates millions of records were included in the exposed set.
Types Of Data Potentially Exposed
- Names and dates of birth
- Contact information
- Social Security numbers and other identifiers
- Employment and assignment details
Investigation And Related Incidents
The Pentagon has been asked for comment. Separately, the FBI is investigating an apparent attack on its jobs website by a criminal group known as ShinyHunters, which has claimed to have obtained large amounts of internal personnel data. Other recent large-scale breaches — including an incident that may have exposed more than 153 million driver's licenses — have heightened concerns among security experts that aggregated records can enable targeted spying, identity theft and phishing campaigns.
Risk: Security analysts warn that access to troves of personnel records raises the chance of follow-on attacks, including sophisticated phishing, identity theft and potential targeting of individuals with sensitive roles.
What DMDC Is Doing
DMDC told affected individuals it has patched the file-sharing vulnerability and is offering one year of credit monitoring and identity restoration services through IDX to those notified. The center stated there is no current indication of misuse of specific recipients' data, per the notification letter.
What You Can Do Now
- Accept and activate any credit monitoring or identity-restoration services offered through DMDC/IDX.
- Place a free credit freeze with Equifax, Experian and TransUnion via the FTC to restrict new credit accounts.
- Review financial and account statements for unusual activity and enable multi-factor authentication where possible.
- Be especially cautious of unsolicited emails, calls or text messages that ask for personal details—verify requests through official channels before responding.
- Active-duty personnel and National Guard members should follow any additional guidance from their chain of command and consider available monitoring services through military channels.
If you believe you were impacted and have not received a notification, check official DMDC guidance and news updates from reputable outlets for the latest instructions.
Help us improve.

































