Unauthorized users exploited a vulnerability in the Defense Manpower Data Center's file-sharing system, accessing unencrypted personnel files from about October 2025 until the flaw was detected on July 16, 2026. The breach may affect roughly 4 million current and former Department of Defense personnel. Exposed information reportedly includes names, dates of birth, contact and demographic data, unencrypted Social Security numbers, and in some cases military occupational specialty or equivalent role codes.
DMDC remediated the vulnerability and restored the affected system, detecting and containing the intrusion in July before notifying individuals on September 18. It offered 12 months of IDX credit-monitoring and identity-restoration services; no malicious use had been reported at publication. The incident has not been attributed, and the exploited vulnerability has not been disclosed, but the combination of identity data and military-role information creates substantial identity-fraud and counterintelligence risk, potentially enabling adversaries to identify and target service members, veterans, and their families.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
DMDC sent breach notifications to affected individuals and offered 12 months of credit monitoring and identity-restoration services through IDX. At the time reported, no malicious use of the exposed data had been identified.
DMDC discovered the vulnerability that enabled the intrusion, patched it, and restored the affected system. The Pentagon reportedly detected and remediated the intrusion after approximately nine months of unauthorized access.
Unauthorized users began accessing a vulnerable DMDC file-sharing server containing unencrypted personnel information. The access reportedly exposed personally identifiable information, including Social Security numbers and military occupational data, affecting potentially about four million people.
The FBI separately warned employees of a breach involving its FBIJobs.gov portal. ShinyHunters claimed responsibility and threatened to publish staff information, including Social Security numbers.
The Department of Defense confirmed that the DMDC breach affected 2.76 million living individuals and 294,000 deceased individuals. The responsible actor remained unidentified, and the Pentagon reported no indication that the exposed data had been misused.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
25 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcearstechnica.com
Open sourcescworld.com
Open sourcehelpnetsecurity.com
Open sourcemalware.news
Open sourceedition.cnn.com
Open sourcereddit.com
Open sourceirs.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.