[Pentagon File-Sharing System Breach Exposes Millions of Personnel Records]
A Pentagon breach that exposed sensitive personnel information for months is raising renewed questions about how well federal agencies monitor their own systems for unauthorized intrusions.
Between October 2025 and July 16 2026, roughly three million records were potentially compromised through a vulnerability in a file‑sharing platform housed at the Defense Manpower Data Center (DMDC). The system stores personal data required by the military and numerous civilian agencies.
“Three million people may grab headlines, but months of hidden, unsecured access to highly sensitive data represent the true cautionary tale,” noted Nitay Milner, co‑founder and CEO of data‑security firm ORION Security.
Nextgov/FCW obtained a copy of the formal notice, which was signed by DMDC Director Katie Griffin. The accessed material included unencrypted personal details such as Social Security numbers, plus, where applicable, names, birth dates, contact information, and military occupational specialties.
“As soon as the security weakness was identified, DMDC launched a full privacy and cybersecurity response following OMB and Department of Defense guidance. We are currently evaluating and strengthening the security posture of the DMDC system,” Griffin added.
According to the correspondence, DMDC applied a patch, restored normal operations, and is offering potential victims one year of free credit‑monitoring and identity‑restoration services.
Military Times first reported the incident a month ago, referencing the same official notice. A defense spokesperson later told CNN that the breach actually impacted approximately 2.76 million living former or active‑duty persons, along with an additional 294,000 deceased individuals.
This revelation arrives amid the FBI’s own probe into a separate intrusion attributed to the criminal hacking group ShinyHunters, which likely also exposed sensitive records tied to intelligence‑gathering personnel.
While no public link ties the two security incidents together, each highlights data that could help attackers identify government workers and craft targeted social‑engineering scams. Such records can also reveal employees whose duties attract foreign intelligence interest.
The DMDC breach is not an isolated event; several weaknesses in federal infrastructure have surfaced in recent years. In December 2024, Chinese state‑sponsored hackers gained access to unclassified documents via a compromised remote‑support service. Earlier in 2025, the judiciary admitted its electronic case‑management system had been breached, and the Congressional Budget Office confirmed unauthorized access to those systems in late fall.
Experts increasingly believe artificial‑intelligence tools will accelerate cyberattacks, allowing hackers to discover vulnerabilities quickly and use stolen personal data to fine‑tune deceptive campaigns.
Milner stress that detecting illicit activity requires agencies to define who collects sensitive information, confirm that access rights are legitimate, and evaluate whether user behavior aligns with expected patterns.
Constant vigilance remains essential even when intrusions do not trigger immediate disruption. Inspection reports indicated that, in the DMDC case, more than nine months passed before the vulnerability was discovered.
Jeff Wichman, senior director of breach preparedness at Semperis, warned that organizations must plan for intrusions despite maintaining strong teams and robust controls.
“Although the FBI and Pentagon possess exceptional responders, these breaches continue to occur and ultimately affect every agency. True resilience depends on a fully tested incident‑response framework that clarifies team responsibilities throughout the full breach lifecycle—from initial discovery and containment through legal and regulatory reporting.”
Wichman further cautioned that new government AI services, including the America.gov chatbot, could create additional pathways for attackers to reach sensitive data if they connect to agency systems. “Each leak triggers a cascade of risk,” he warned. “More government AI deployments may amplify the frequency and impact of compromises.”

