Yovao News · The World, In Focus. From Local to Global, Never Miss a Beat

Hackers Stole Records of 2.8 Million U.S. Military Personnel in Months-Long Breach

Hackers Stole Records of 2.8 Million U.S. Military Personnel in Months-Long Breach

The U.S. government has issued alerts to millions of current and former military personnel, informing them that their personal information was compromised during a prolonged breach of Pentagon records. This incident marks the latest in a series of high-profile thefts involving federal workers’ data.

A notification from the Defense Manpower Data Center (DMDC), which first surfaced on Reddit, revealed that unauthorized users exploited a vulnerability in an unspecified file-sharing system. The intruders accessed the database over a period spanning from October 2025 to mid-July 2026.

The stolen data included personally identifiable information such as Social Security numbers, names, dates of birth, sex, race, and details regarding military service. The DMDC notice emphasized that the affected personnel records were not encrypted.

According to reports from CNN and the Federal News Network, a Pentagon official stated that the breach impacts approximately 2.8 million living individuals and nearly 300,000 deceased persons. For context, the U.S. military comprised 1.3 million active-duty service members as of March.

While the DMDC may not be widely recognized by the general public, it plays a critical role within the Department of Defense. The agency maintains more than 60 million records for military and civilian staff, as well as their families, to determine benefits and entitlements like healthcare and retirement. It also serves as the military’s primary identity management provider, linking service members and contractors to credentials such as smart cards and passwords used to access secure facilities and systems.

“We make sure that the right people get access and the wrong people don’t: security of identity information is paramount,” the DMDC states on its website.

The Department of Defense indicated there is no evidence that the stolen information has been misused, though it did not elaborate on how this conclusion was reached. TechCrunch sought comment from a Pentagon spokesperson regarding any communications from the unidentified hackers but did not receive a response.

This breach follows another significant cyber incident earlier in September, where the ShinyHunters hacking group claimed responsibility for stealing personal data from FBI agents and staff. That event has been described as a “counterintelligence disaster” due to the potential for foreign governments to use the information to profile or coerce federal workers. ShinyHunters has stated they will not release the FBI data publicly.

Both incidents echo similar large-scale thefts of government personnel records, most notably the 2015 breach of the Office of Personnel Management, which exposed the private records of over 22 million federal employees and is broadly attributed to Chinese hackers.

4 responses to “Hackers Stole Records of 2.8 Million U.S. Military Personnel in Months-Long Breach”

  1. This echoes the 2015 OPM breach so closely. Is the DoD really investing in modern cybersecurity, or just patching holes?

  2. No evidence of misuse? I’m skeptical. They often claim that until it’s too late. Identity theft is inevitable here.

  3. Wait, nearly 300,000 deceased persons records were stolen too? That’s chilling. What do hackers even want with the dead?

  4. Leaving SSNs unencrypted for 2.8 million people is negligent beyond belief. How did this pass basic security audits?

Leave a Reply

Your email address will not be published. Required fields are marked *