Pentagon Breach Exposed Social Security Numbers of 2.76 Million Living People
Unauthorized users had access to a Defense Manpower Data Center system for nine months. Another 294,000 records belong to people who have died, and the data was not encrypted.

A Pentagon personnel system was breached for roughly nine months, exposing the Social Security numbers and other personal details of about 2.76 million living people and another 294,000 people who have died, a defense official confirmed to TIME on Tuesday.
The Defense Manpower Data Center, known as DMDC, found the problem on July 16, 2026. Officials say a small number of unauthorized users accessed the system between October 2025 and that date. The center keeps records on more than 60 million people, including service members, civilian employees, contractors, family members, retirees and veterans.
Each affected person's record included a Social Security number and at least one other item, such as a name, date of birth, contact information, sex, race or military job information. The Pentagon's notification letter said the data was not encrypted, according to ABC News and other outlets that reviewed it.
"Upon discovery, DMDC immediately remediated the vulnerability," a defense official told ABC News. The vulnerability was patched in July. The department says it has found no evidence that the stolen information has been misused.
The exposure of job details is what makes the breach more than an identity-theft problem. Combined with other datasets that use Social Security numbers as identifiers, the information could give a foreign adversary a clearer picture of who does what for the U.S. military and where, according to reporting by CNN and others.
Notification letters went out on September 18, and Military Times first reported the breach on September 24. That means affected people learned of it more than two months after the department found the hole. The Pentagon is offering one year of credit monitoring and identity restoration through IDX, and free credit freezes are available from Equifax, Experian and TransUnion. Affected people can call 1-855-744-4556 or visit response.idx.us/DMDC.
The breach follows other recent hacks of federal data. Dutch police this week arrested a suspected 24-year-old member of the ShinyHunters group, which claims it breached the FBI's jobs database that holds sensitive employee data. That case is separate from the Pentagon incident, and officials have not said who was behind the DMDC intrusion.
For those affected, the practical risk is long-lived. A Social Security number cannot be replaced easily, and one year of monitoring will expire well before the exposed numbers stop being useful to criminals or foreign intelligence services.
The Defense Department has not said how the unauthorized users got in, and it has not said whether the intruders were criminals or agents of a foreign government. Lawmakers on the armed services committees are likely to ask why a system holding the records of tens of millions of people left Social Security numbers unencrypted for so long.


