The U.S. Department of Defense is notifying millions of current and former service members that their personal information was stolen in a months-long breach of the Pentagon's personnel records. According to a breach notification from the Defense Manpower Data Center (DMDC) circulating online, several unauthorized users exploited a vulnerability in an unspecified file-sharing system between October 2025 and mid-July 2026.

The exposed data includes Social Security numbers along with names, dates of birth, sex, race and details of military service. The notice states that the personnel records were unencrypted. Citing a Pentagon official, CNN and Federal News Network put the figure at roughly 2.8 million living people, plus close to 300,000 deceased individuals — a total that dwarfs the 1.3 million active service members the U.S. military had as of March.

The DMDC is little known publicly but central to how the military administers itself. It holds more than 60 million records for service members, civilian staff and their families, underpinning benefits such as healthcare and retirement, and it acts as the military's primary identity provider, tying people to the credentials — smart cards, passwords — that open Pentagon systems, buildings and bases.

The department says it has no indication the data has been misused, but has not explained how it reached that conclusion, and the identity of the intruders is unknown. The incident follows a September breach at the FBI attributed to the ShinyHunters group, which claimed to have taken data on most of the bureau's agents and staff, and echoes the 2015 compromise of the Office of Personnel Management, blamed on China, that exposed records on more than 22 million government employees. Stolen personnel files are considered especially dangerous because they let a foreign government profile, target or coerce staff.