The Defense Manpower Data Center — the Pentagon office that has held the personnel records of the US military since 1974 — has told 2.76 million living people and the next of kin of roughly 294,000 deceased ones that their records were reachable by unauthorised users.
The access ran from October 2025 until DMDC found the flaw on 16 July 2026. That is nine months. The system was a file-sharing service, the vulnerability in it was unpatched, and the personally identifiable information sitting on the server was not encrypted.
What was in the files
The exposed data varies by person, and the combination is the problem rather than any single field.
Social Security numbers, paired with names, dates of birth, contact information, race, sex, and military job specialties.
A Social Security number is the one identifier in American life that cannot be reissued on request. A date of birth does not change. Put them together with a name and you have the basis for opening credit, filing a fraudulent tax return, or passing the knowledge-based checks that still gate access to accounts.
The job specialty field is what makes this different from a retail breach. It converts a list of identities into a list of identities sorted by what each person did — linguists, cryptologic technicians, intelligence analysts, medical personnel — which is a targeting aid for anyone building a social engineering campaign or an approach to a cleared individual.
No indication of misuse is not the same as no misuse
DMDC says it has no indications of misuse of the accessed information. It has not said who accessed the files, or whether anything was copied.
Those two statements sit badly together. Misuse of a Social Security number surfaces when a credit application is filed or a tax return is rejected, often months or years later and at the victim's end rather than the agency's. An organisation that does not know what left cannot have evidence that it is being used, and the absence of evidence here is a description of visibility, not of safety.
That is the same shape as the French tax agency breach we covered, where the agency learned of the theft from the thief. Government bodies hold the records that matter most and tend to find out last.
The timeline is the finding
Set the dates out and the shape is clear. Access begins in October 2025. It is discovered in July 2026. Letters reach people in September 2026.
Nine months of exposure, then roughly two more before the people affected could act. For a breach involving credentials, that delay is survivable because credentials can be changed during it. For identity data, the delay is the harm: the window in which someone could have opened an account in your name is a window you did not know to watch.
The remedy offered is twelve months of credit monitoring. For a Social Security number, twelve months is a fraction of the useful life of the stolen item. Credit monitoring also only reports what has already happened.
The ordinary failure underneath
Nothing exotic caused this. A file-sharing system with an unpatched vulnerability, serving files that held unencrypted personal data.
File transfer products have been the reliable source of mass data breaches for several years now, for a plain reason: they are built to be reachable from outside, they are given large volumes of exactly the data worth stealing, and they tend to be owned by whoever installed them rather than by a security team.
The second half is the avoidable part. Encryption at rest would not have stopped the access, but it would have changed what the access was worth. Three million Social Security numbers were sitting in a form that could simply be read.
What to do
- If you got a letter, freeze your credit rather than only monitoring it. A freeze prevents new accounts; monitoring tells you after one was opened.
- Treat unexpected contact referencing your service history as hostile. The job specialty field means an approach can be convincingly specific.
- File your tax return early. Return fraud is one of the first uses of a stolen number and the position goes to whoever files first.
- If you run a file transfer service, find out today what is sitting on it, how long it has been there, and whether it is encrypted at rest. Those three answers are the entire lesson here.
What is not established
- Who accessed the files. DMDC has not said, and has not attributed the activity.
- Whether any data was copied, which DMDC also does not state.
- How the vulnerability was introduced, and why it was unpatched for nine months.
- Why personally identifiable information on that system was stored unencrypted.