Pentagon breach revealed sensitive data on nearly 3 million people
A breach of the Pentagon’s vast personnel database revealed sensitive information belonging to a large number of service members, including Social Security numbers and details about the jobs they held, according to a US defense official.
The breach affected 2.76 million living people and another 294,000 people who died, the official said. The scope and sensitivity of the information exposed could raise national security concerns, particularly because the files contained details of work carried out by military and civilian personnel.
“A Defense Manpower Data Center (DMDC) information system experienced unauthorized access to personally identifiable information by a small number of unauthorized users between October 2025 and July 2026. Upon discovery, DMDC immediately remediated the vulnerability,” the official said.

Julia Demaree Nikhinson/AP – PHOTO: The Pentagon is seen from Air Force One, September 26, 2026, in Washington, DC
The Defense Manpower Data Center is one of the Pentagon’s primary repositories for personnel records, holding information on active duty and reserve troops, civilian employees, contractors, retirees, veterans and military family members.
FBI investigating possible cyber breach of job application site: sources
The agency manages more than 60 million personal files. The Military Times first reported the breach last week.
The unauthorized access extended from October 2025 to July, when DMDC discovered the vulnerability and patched the affected system, according to the defense official, adding that there is yet no evidence that the exposed data was misused.
Defense officials said they have found no evidence so far that the exposed information was misused and that they are offering identity protection and credit monitoring resources.
News of the Pentagon breach comes as the FBI sent a notice to employees Friday outlining their response to a breach of its job portal FBIJobs.gov.
A malicious actor said it would release data including FBI employees’ names, home addresses, personal and work contact information, Social Security numbers, date of birth and emergency contact information, sources told ABC News, and the bureau is operating as if every FBI employee’s personal information was compromised.
But in a statement to the New York Times and 404 Media on Monday, hacking group Shinyhunters claimed it would not release the data as it had previously announced.
“From the very beginning of this event, we have unequivocally and assiduously emphasized that this was NOT extortion, ransom, or financial motivation,” the statement said. “This was a marketing campaign to protect our company and actively combat misinformation. If we made this statement normally, such attention to our words and intentions would never have been more widespread.”
ABC News has not independently verified the group’s claims.
Affected employees also began being notified, and the FBI said the affected system – FBIJobs.gov – was unclassified.
The FBI also issued a warning to those who may be affected, advising them to remain aware of the situation and not respond to suspicious calls. Internal information sessions will also be held for affected employees.
It also says, according to the warning described to ABC News, that employees should not speak to the media and that if media “trespass on the property,” employees should call 911.
Gn world