Pentagon Personnel Agency Says a File-Sharing Flaw Exposed Troop Data for Months

  • Tech
  • October 1, 2026
  • 0 Comments

The letter arrived without a number. It told recipients that “a small number of unauthorized users” had reached a file-sharing system run by the Defense Manpower Data Center, the Pentagon’s central repository for personnel records, and that the files they touched held names, dates of birth, gender, race and Social Security numbers of current and retired service members.

The intrusion ran from October 2025 until mid-July 2026, when the center found and patched a vulnerability in its file-sharing system. For roughly nine months, unauthorized users moved through a server holding unencrypted personal data, and the Pentagon has not said how many people were affected or who accessed the files. TechCrunch reported the breach on Sept. 30, the latest in a string of federal employee data thefts in recent months.

The scale of the target is what alarms security experts. The DMDC holds more than 60 million records covering military and civilian personnel, contractors, family members, retirees and veterans, and it describes itself as the department’s central source for identifying, authenticating and authorizing people during and after their affiliation with the military. A single flaw in one file-sharing system became a door into a population the government holds data on from enlistment to death.

The exposed records varied by person. Some contained Social Security numbers alongside names and dates of birth. Others included demographic data and military occupational specialties, the codes that record what a service member actually did. That last category is what separates this breach from an ordinary identity-theft incident.

A foreign intelligence service holding names, Social Security numbers and occupational specialties could map the composition of the force, identify individuals for recruitment or targeting, and learn which skills are concentrated where. It is the kind of file that makes counterintelligence officers uneasy precisely because it is administrative and therefore comprehensive.

The discovery came on July 16, when the center detected the vulnerability, patched the system and restored it. Notification letters began reaching victims in mid-September, and Military Times first reported the breach after reviewing one such letter. The Pentagon has said it “does not have any indications of misuse” of the data, the notification said.

Absence of evidence, security analysts caution, is not evidence of absence when records sat exposed for nine months. Data stolen quietly is often held quietly, and the value of military personnel files does not expire the way a credit card number does. A Social Security number and a service record remain useful to an adversary for decades.

The letters did not come with a figure for how many were exposed, and victims were left to weigh their own exposure. A stolen Social Security number is the raw material for tax-refund fraud, synthetic accounts and loans opened in another person’s name, and service members are frequent targets of scams that exploit the predictability of military pay and deployment schedules.

The DMDC is not a peripheral office. Founded in 1974, it is the operational arm that authorizes benefits and entitlements and holds the training, financial and personnel data used to manage the entire department. Its records cover everyone who has passed through the force, which is why a breach there cuts wider than an intrusion at any single command.

This is not the first time a federal personnel system has leaked. The 2015 breach of the Office of Personnel Management exposed background-investigation files on more than 20 million people, including 5.6 million sets of fingerprints, and U.S. officials attributed it to actors linked to the Chinese government. That episode changed how Washington treats the data it holds on its own employees; the DMDC incident shows the lesson has not fully stuck.

The breach also lands inside a broader run of intrusions. Federal agencies and their contractors have reported a steady series of data losses in recent months, and personnel systems remain a favored target because they concentrate the most sensitive attributes of a person in one place, held for a lifetime rather than the length of a contract. Flaws in widely used file-transfer and file-sharing tools have been among the most common entry points for large-scale data theft across government and industry in recent years.

For the service members who received the letters, the practical question is what to do with a Social Security number that has been exposed for months. Under federal rules, agencies must tell people when their personally identifiable information has been exposed, and the notice campaign is expected to continue for weeks as the center works through its records. For the department, the harder question is how a central personnel system left a file-sharing flaw open long enough for a nine-month intrusion, and whether the records of people who cannot easily walk away from the military are protected as carefully as the weapons they carry.

Related Posts

  • October 1, 2026
  • 11 views
Micron’s Record Quarter Gives Way to a Spending Warning

Micron Technology delivered its sixth consecutive record quarter after the market closed on September 30, and its shares fell anyway. The chip maker cleared every target it had set for…

  • October 1, 2026
  • 11 views
Samsung Defers Its Most Expensive Machines to 2030

Samsung Electronics bought two of the most advanced chipmaking tools ever built, then decided to let them wait. ChangMin Park, a senior technology executive at the Korean company, told engineers…