The Pentagon has confirmed a Defense Manpower Data Center data breach affecting approximately 2.76 million living people. A Defense Department official said unauthorized users accessed files containing personally identifiable information, including Social Security numbers and details about some individuals’ work.
What happened in the Pentagon DMDC data breach
According to statements provided by a U.S. defense official to ABC News and TIME, unauthorized access occurred in a Defense Manpower Data Center information system between October 2025 and July 2026.
The Defense Manpower Data Center, commonly called DMDC, maintains personnel and administrative records used across the Defense Department. Its data covers populations that can include active-duty and reserve service members, civilian employees, contractors, retirees, veterans, and military family members.
The Defense Department said DMDC discovered the security issue in July and immediately remediated the vulnerability. A notification letter reviewed by Military Times and cited by TIME reportedly says the affected technology was a file-sharing system.
What the Pentagon has confirmed
A Defense Department official confirmed that the incident affected approximately 2.76 million living individuals and 294,000 deceased individuals. The exposed information varied by person.
Public reporting based on the Pentagon’s statements and breach notifications says the affected files may contain:
- Names
- Social Security numbers
- Dates of birth
- Contact information
- Employment and job-related details
- Other personnel information maintained by DMDC
The Pentagon says affected living individuals are being notified by mail. It is also offering one year of credit monitoring and identity-restoration services through IDX.
What remains unknown
The Defense Department has not publicly identified the unauthorized users, disclosed the exact vulnerability involved, or attributed the breach to a criminal or nation-state group.
Officials have also not publicly provided a complete list of every data field accessed. The information exposed differs among affected individuals.
The Pentagon says it has not found evidence that the exposed information has been misused. That does not eliminate future risk, especially because Social Security numbers, contact information, and employment details can support identity theft and convincing impersonation attempts.
Who may be affected
DMDC supports personnel programs across the military community. Potentially affected populations may include current and former service members, Defense Department civilians, contractors, retirees, veterans, and military family members whose information was stored in the accessed files.
Only an official notification can confirm whether a specific person was affected. Individuals should be cautious of messages that claim to verify breach status but request passwords, payment, one-time security codes, or sensitive documents.
Why the DMDC breach matters
The combination of identity data and job details creates risks beyond ordinary spam. Attackers can use accurate employment information to make phishing emails, phone calls, and account-recovery attempts appear legitimate.
Businesses that employ veterans, reservists, military spouses, former Defense Department personnel, or federal contractors should expect an increased possibility of targeted impersonation. Criminals may pose as government offices, benefits administrators, financial institutions, or workplace support staff.
Practical defensive actions
- Verify breach notices independently: Use contact information from an official government website or the mailed notification instead of links or phone numbers in unsolicited messages.
- Freeze credit files: A credit freeze at Equifax, Experian, and TransUnion can make it harder for criminals to open new accounts using stolen identity data.
- Use the offered monitoring: Affected individuals should review the official letter and consider enrolling in the Pentagon-provided identity protection service through the verified enrollment channel.
- Protect email accounts: Use a unique password and phishing-resistant multi-factor authentication where available. Email access can let an attacker reset other accounts.
- Review financial and benefits accounts: Watch for unfamiliar changes, applications, password resets, or contact-information updates.
- Brief employees: Organizations with military-connected staff should warn them about targeted calls and messages referencing their service, job, benefits, or family information.
- Require independent verification: Sensitive workplace requests involving payroll, access, personnel records, or money transfers should be confirmed through a second trusted channel.
- Report suspected identity theft: Victims can use the Federal Trade Commission’s IdentityTheft.gov service to create a recovery plan.