"a small number of unauthorized users" had access to their sensitive data, the Defense Manpower Data Center (DMDC) told affected military personnel in breach notification letters shared online.
DMDC notification and immediate response
The Pentagon's Defense Manpower Data Center is notifying millions of military service members that hackers stole data after breaching the Pentagon's human resources management system, the DMDC said in letters seen by affected individuals. The agency told recipients it "immediately initiated privacy and cybersecurity incident response actions in accordance with Office of Management and Budget and Department guidelines and policies" and that it is "taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system."
The DMDC operates as an operational support center that the source says was founded in 1974 and stores more than 60 million records used to authorize benefits and entitlements, as well as training, financial, and other data for the Department of Defense. The DMDC also runs DoD personnel programs and conducts research and analysis as directed by the Office of the Secretary of Defense (OUSD).
Scale and nature of the stolen records
Pentagon officials told Federal News Network the breach affects more than 3 million people: nearly 2.8 million living individuals and approximately 294,000 "deceased individuals." The stolen information varies by person but can include Social Security numbers, names, dates of birth, contact information, sex, race, and military personnel information, according to the DMDC notification letters reproduced online.
The DMDC highlighted the breadth of systems and users that rely on its services, saying the data and access it provides "support so many vital government entities, including the legislative branch, human services, national defense, labor, healthcare, finance, veterans affairs, research, and more."

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildHow the breach happened and the timeline
The DMDC told affected individuals that "a small number of unauthorized users" had access to sensitive data between October 2025 and July 2026 after exploiting a vulnerability in its file-sharing systems. The source states the access window ran from October 2025 through July 2026; discovery of the vulnerability prompted the DMDC's incident response actions.
The Pentagon is offering 12 months of free credit monitoring services through the IDX data breach and recovery service provider; affected individuals must enroll by August 19, 2027, the notification letters say. When BleepingComputer sought additional comment, a Pentagon spokesperson was not immediately available, the outlet reported.
Related claims: ShinyHunters and an FBIjobs.gov incident
The DMDC breach follows another major claim reported by the same source: the ShinyHunters extortion gang said it breached the FBI's FBIjobs.gov site using an Oracle PeopleSoft zero-day. ShinyHunters claimed to have stolen several terabytes of data — including names, Social Security numbers, home addresses, and assignments — allegedly belonging to "almost ALL FBI Agents," and including records for members of the FBI Remote Operations Unit, the group said.
ShinyHunters told BleepingComputer that the FBI breach was not financially motivated and that the group does not intend to publish the stolen FBI data or extort the bureau.
What this means for technologists, policymakers, and affected individuals
- Technologists and security teams: The incident centers on a file-sharing systems vulnerability and a months-long access window (October 2025–July 2026). Teams responsible for DoD and contractor systems will be watching how the DMDC assesses and enhances its cybersecurity posture and whether remediation focuses on file-sharing configurations, patching, or access controls.
- Policymakers and regulators: The DMDC cited compliance with Office of Management and Budget and Department guidelines in its response. Regulators will follow enrollment details for the IDX credit monitoring offer and the extent to which notification and remediation meet federal guidance for breaches involving personally identifiable information.
- Affected military personnel and families: Nearly 2.8 million living individuals and about 294,000 deceased individuals are included in the reported total; the DMDC is offering twelve months of IDX credit monitoring for those who enroll by August 19, 2027. Those notified will need to review the enrollment instructions provided in their letters and monitor for misuse of Social Security numbers and other exposed data.
The DMDC breach places a vast centralized personnel repository at the center of a prolonged incident: more than 3 million records touched, a multi-month access window, and a notification process that includes an enrollment deadline for credit monitoring. The notification and the DMDC's promise of remediation set out immediate steps for affected individuals, but the breadth of records and the overlap with other high-profile breach claims underscore continuing questions about how large, cross-cutting government data stores are protected and how quickly vulnerabilities in shared services are discovered and closed.




