America
Pentagon breach exposes personal records of three million people
A cyberattack targeting the US Department of War’s personnel database has resulted in the leak of personal information belonging to approximately 3 million people.
Speaking to ABC News, a Pentagon official stated that the system accessed by unauthorised individuals contained the records of 2,760,000 living persons and 294,000 deceased individuals.
The Military Times portal, which first broke the news, had reported the number of affected individuals as approximately 4 million based on two sources. The Pentagon official subsequently conveyed different figures to ABC News.
The leak encompasses Social Security numbers and duty information belonging to military personnel and civilian employees. According to an official notification examined by Military Times, the compromised records may also include names, dates of birth, contact information, sex, race, and military occupational specialties.
The unauthorised access to the information system of the Defense Manpower Data Center (DMDC) lasted for approximately nine months, between October 2025 and 16 July 2026.
ABC News reported that the access in question was obtained by a small number of third-party users. The vulnerability was closed after it was identified.
The DMDC is considered one of the Pentagon’s primary personnel records centres. More than 60 million records belonging to active-duty personnel, reservists, civilian staff, contractors, retirees, veterans, and military family members are stored at the centre.
The Pentagon has not detected any evidence that the leaked data has been misused. Military Times reported that affected individuals were offered identity restoration and credit history monitoring services.
A similar data breach previously occurred on the Federal Bureau of Investigation’s (FBI) recruitment website, FBIJobs.gov. According to information obtained by ABC News from internal communications and sources, the FBI is considering the possibility that data belonging to its entire staff may have been stolen.
The New York Times (NYT) examined a portion of the stolen FBI records. Home addresses, telephone numbers, official email addresses, Social Security numbers, dates of birth, hiring dates, and emergency contact details for relatives were identified within these documents.
The database also contained unit designations, duty roles, and information regarding the supervisors of personnel. Some records revealed assignments within counterintelligence and counternarcotics units, as well as departments examining threats originating from Russia, China, and Iran.
Ciaran Martin, the former head of the UK National Cyber Security Centre, noted that this type of breach could directly affect the FBI’s operational capabilities.
The hacker group known as ShinyHunters had announced that it had seized medical data and security clearance records alongside files belonging to tens of thousands of active and former FBI employees.
Experts evaluating the matter for the NYT warned that this information could be used to track agents, threaten their families, or compile dossiers by foreign intelligence services.
The ShinyHunters group initially threatened to release the data unless the bureau withdrew an advisory it had published concerning the group’s attack methods.
The group later asserted that it had never intended to leak the information and characterised its action as an advertising campaign.
In a report published in May, Reuters noted that the personal data of US military personnel had been used in surveillance and attack preparations.
According to the agency, Washington’s adversaries gained the ability to pinpoint areas where troops were concentrated by exploiting commercially available location data. US lawmakers at the time criticised the Pentagon for failing to adequately protect the personal data of military personnel.