A security failure at the Pentagon has expoed the Social Security numbers and employment data of 2.76 million military and civilian personnel. The breach also compromised the records of 294,000 deceased individuals.

Advertisement

The 2.76 million records left unencrypted

The Defense Manpower Data Center oversaw a database where sensitive personal identifiers were stored without encryption, leaving them vulnerable to unauthorized access. according to the report, the exposed files contained Social Security numbers and specific employment details for the entirety of the U.S. defense workforce,including active-duty soldiers, reservists, contractors, and retirees.

This failure is particularly acute because Social Security numbers are foundational to identity verification and financial transactions in the United States. While the Pentagon's public information office stated that no classified or strategic operational data was leaked, the exposure of personal identifiers creates a massive surface area for long-term identity theft and financial fraud targeting the military community.

A nine-month window from October 2025 to July 2026

The timeline of the breach reveals a significant gap in detection, as unauthorized users were able to access the Pentagon's records for approximately nine months... As a Pentagon official confirmed, the breach persisted from October 2025 until it was finally discovered in a file-sharing system on July 16, 2026.

The delay between discovery and notification further complicated the situation. The Defense Manpower Data Center did not begin alerting the millions of affected individuals until September 18, 2026. this two-month lag between the discovery of the flaw and the notification of victims may have hindered the ability of service members to secure their credit reports in a timely manner.

The largest personnel exposure in U.S. military history

This incident represents the most extensive data exposure of its kind ever recorded within the U.S. military . The breach echoes a broader, systemic struggle within government agencies to migrate legacy file-sharing systems to secure, encrypted cloud storage solutions. By leaving records on shared servers without basic encryption, the Pentagon fell short of modern cybersecurity standards.

In response to the crisis, the Defense Security Service has issued a mandatory directive requiring all agencies to enforce encryption on all personnel records. This move is part of a wider effort by federal cybersecurity experts to overhaul encryption protocols across all defense networks to ensure that a single flaw in a file-sharing system cannot compromise millions of identities.

Who accessed the Defense Manpower Data Center's files?

Despite the scale of the leak,several critical questions remain unanswered. The Pentagon has not identified the specific actors or third parties who accessed the database, nor has it clarified if the breach was the result of a targeted state-sponsored attack or a opportunistic discovery by a random actor. While the report says there is no indication the data has been misused to date, investigators are still searching for evidence of phishing schemes or identity theft.

Furthermore, there is a glaring lack of clarity regarding the 294,000 deceased individuals whose records were exposed. It remains unknown how the Pentagon intends to notify the families of these individuals about the privacy violation, or what remediation steps are available for the estates of the deceased.