A massive Pentagon hack sees the records of 2.7 million US military personnel leaked during months of data breach: names, military service records and Social Security numbers revealed.
- The breach exposed the PII of three million current and former people affiliated with the Department of Defense
- Attackers accessed unencrypted data for months through vulnerable file-sharing system
- The stolen records included social security numbers, military duties and confidential personnel details.
Three million people, both living and deceased, who work and used to work for a division of the US Department of War (DoW, also known as DoD), had their personally identifiable information (PII) stolen in a cyberattack that went undetected for months.
The War Department runs a component called the Defense Manpower Data Center (DMDC). It is the Department of Defense’s personal data agency that collects and maintains data on personnel and the workforce. Manages large databases with information on military personnel, civilian employees, contractors, and others connected to the U.S. defense community.
The DMDC also provides data and analytical services to support military operations.
Latest videos ofTechnologyRadar
Confirmed breach
About two weeks ago, a person shared a photo on Reddit showing a data breach notification letter they received in their mail. In the letter, the DMDC explained what happened and offered complementary identity theft monitoring services:
“On July 16, 2026, a security vulnerability was discovered in a DMDC file sharing system, allowing unauthorized users to access files,” the letter reads. “DMDC immediately updated the file sharing system to patch the vulnerability and the system was restored.”
A subsequent investigation determined that someone used the flaw to access servers containing unencrypted PII in October 2025. Between then and July 2026, they extracted all types of information, including Social Security numbers (SSN), full names, dates of birth, contact information, gender, race, and military personnel information such as occupational specialty.
Speaking to CNN, a War Department official confirmed the breach and said it affects 2.76 million “living individuals” and 294,000 deaths. According to the DMDC website, the organization manages more than 60 million records.
At press time, we were still missing key details. We don’t know which file sharing system was targeted or what the flaw is. Just a few days ago, secure file-sharing service Kiteworks warned its customers to shut down their servers for nine hours in anticipation of a cyberattack.
Links to Kiteworks?
Kiteworks is a large secure file sharing service that works with government agencies, including US federal, state, and local governments. On its website, the company explicitly says that defense contractors use its platform to secure CUI and FCI that they exchange with the Department of Defense, although it does not confirm working directly with the agency. Kiteworks also markets dedicated government solutions and says its platform is authorized by FedRAMP for federal use.
Cybercriminals like Cl0p are known to attack this type of service. A few years ago, major breaches in MOVEit and GoAnywhere MFT led to data leaks across thousands of organizations. The damage is in the millions.
Later in the letter, the DoW says that so far there is “no indication” that the files have been misused, although it is safe to assume that the files will be sold on the black market or used for highly personalized phishing emails. Attackers could use the information to trick victims into sharing their login credentials, ultimately accessing even more sensitive DoW servers and causing even greater damage.
CNN says “occupational specialty” information could be extremely valuable to foreign nation-state threat actors, because it can be combined with Social Security numbers to get a “clearer read on who does what for the U.S. military in various parts of the world.”
The DMDC said it fixed the flaw as soon as it discovered it, so it’s safe to assume it wasn’t a zero-day. In addition to “taking appropriate measures to assess and improve the cybersecurity posture of the DMDC system,” the agency also said it is now offering 12 months of credit monitoring services through IDX.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment