"Hackers lived in Pentagon HR files for 10 months and took 3 million records"
Key takeaways
- Attackers had access to the Defense Manpower Data Center from October 2025 to July 2026
- Around 2.8 million living people and 294,000 deceased people are affected
- Stolen data includes Social Security numbers, dates of birth, contact details and military personnel records
- The Pentagon is offering 12 months of IDX credit monitoring, with enrolment open until 19 August 2027
Ten months is a long time to be inside
The US Department of Defense has started posting breach letters to millions of people, and the timeline in them is the part that should make you wince. According to the letters, attackers had access to systems run by the Defense Manpower Data Center (DMDC) from October 2025 until July 2026. That is ten months of quiet access to one of the largest personnel databases on the planet.
The DMDC told recipients that "a small number of unauthorised users" got in by exploiting a vulnerability in its file-sharing systems. Pentagon officials told Federal News Network the breach affects more than 3 million people: roughly 2.8 million living individuals and 294,000 who have died.
What was taken
The data varies by person, but the list is about as bad as personnel data gets:
- Social Security numbers
- Names and dates of birth
- Contact information
- Sex and race
- Military personnel information
The DMDC has been around since 1974 and holds more than 60 million records covering service members, civilians, contractors, families, retirees and veterans. It feeds benefits, entitlements and a long list of other government systems. Breaches of that kind of hub tend to be the gift that keeps on giving for fraudsters.
The Pentagon says it has no indication the data has been misused. That is the standard line, and it is worth treating it as "not yet" rather than "never".
A bad month for US government HR systems
This lands a week after ShinyHunters claimed it had breached the FBI through an Oracle PeopleSoft zero-day, pulling data on agents and job applicants. The two incidents are not known to be connected. The pattern is the point. HR and personnel platforms are where government agencies keep their most sensitive identity data, and they are often old, sprawling and connected to everything.
File-sharing systems keep turning up as the entry point too. They sit on the edge of the network, they are built to move data out, and they are rarely the system anyone is watching closely. Ten months of undetected access says the monitoring was not there.
What affected people should do
The Pentagon is offering 12 months of free credit monitoring through IDX, and you have until 19 August 2027 to enrol. Take it, but do not stop there.
Freeze your credit. In the US, a freeze at Equifax, Experian and TransUnion is free and stops new accounts being opened in your name. Monitoring tells you after the fact. A freeze stops it happening.
Expect targeted scams. Military records plus contact details make for very convincing phishing. Treat any call, text or email that references your service history, benefits or the breach itself as suspect until you have verified it through an official number.
Lock down your logins. Stolen identity data is often used to social-engineer account recovery. Moving your email and bank accounts to phishing-resistant sign-in, such as a hardware security key like the YubiKey 5C NFC, makes that much harder.
The uncomfortable takeaway is that you cannot change a Social Security number the way you change a password. Once it is out, defence shifts to making the number less useful to whoever has it.
Some links in this article are affiliate links. We only recommend products we think are worth your time.