
A flaw in a Pentagon file-sharing system let unauthorized users read personnel records for roughly nine months. That server belonged to the Defense Manpower Data Center (DMDC), which keeps personnel data for the US military. The files held Social Security numbers and other details, and the data sat unencrypted.
A Defense Department official has now put the count at 3.05 million people. That total covers 2.76 million living individuals and 294,000 who have died. The Pentagon still has not said who got in.
What the Notification Letter Says
DMDC began notifying affected people with a letter dated September 18, 2026. One recipient shared a copy online, and two defense officials confirmed its authenticity to Military Times.
According to the letter, DMDC found a security vulnerability in a file-sharing system on July 16, 2026. That flaw allowed unauthorized users to access files. Afterwards, analysis showed that a “small number” of them had reached a server with unencrypted personal data. Their access ran from October 2025 until the day of discovery.
DMDC says it patched the system as soon as it found the flaw, then restored it. The letter does not name the file-sharing product. It does not describe the vulnerability either.
Each affected person gets 12 months of credit monitoring and identity restoration through IDX, a contractor. The department also states that it has no indication of misuse so far.
The Count Moved From Four Million to Three
An early estimate came from Military Times on September 24. Two people familiar with the incident said about four million Defense Department personnel might be affected. At that point, the department had not confirmed any number.
Four days later, a Pentagon official gave CNN and Federal News Network the figure now in use. Of the 3.05 million people, 294,000 are deceased former defense personnel or their dependents.
The letter itself contains no total. So the only confirmed figure comes from a single official statement, made ten days after the date on the letter.
For scale, DMDC held at least 60 million records as of fiscal year 2024. Those cover troops, veterans, civilian staff, contractors, retirees and military families. DMDC also runs identity verification for every Defense Department ID card holder.
What the Exposed Records Contain
The letter describes a Social Security number plus at least one more identifier. Depending on the person, that might be a name, birth date, contact details, sex or race. Some records also carry military personnel information, such as occupational specialty.
That last field is what makes this breach more than an identity theft risk. A Social Security number links neatly to commercial datasets. Combined with a job specialty, it can show who does what inside the US military.
Justin Sherman, who studies the data broker industry, made a similar point to CNN. In his view, a foreign adversary holding the trove could use it for phishing, profiling and intelligence approaches. The timing adds weight too, because US Central Command told lawmakers this spring about threat reports involving adversaries exploiting commercial location data against personnel.
3 Million Records, and They Don’t Expire
DMDC is the Defense Department’s central source for identifying, authenticating and authorizing personnel during and after their service, so a single office holds records on troops, veterans, civilian staff, contractors, retirees and families.
What the Pentagon Has Not Answered
Several basic questions remain open. When Federal News Network asked who accessed the data, the Pentagon official declined to answer. The same went for whether the affected people belong to a particular group and whether the breach was intentional. Nor would the official say why personal data sat on an unencrypted server.
Meanwhile, no known criminal group has claimed the intrusion.
How DMDC finally spotted the flaw also remains unknown. The letter gives a discovery date, not a discovery method. That gap matters, since the method would show whether monitoring caught the access or something else surfaced it after nine months.
File-Sharing Platforms Keep Showing Up in Breach Reports
DMDC has not named its product, and nothing links this incident to any specific vendor. Still, the category has a long record of trouble.
In the same week, Kiteworks asked customers worldwide to shut down their servers for six hours. The company acted after federal intelligence authorities warned it of a possible imminent attack. Kiteworks later found no sign of compromise and patched a critical flaw in a feature used by less than 1% of customers. A federal warning was enough to take a file-sharing platform offline, which says a lot about the risk this category carries.
The company’s earlier history explains that caution. While it still traded as Accellion, the Clop gang used zero-days in its legacy File Transfer Appliance against customers. Of the 300 customers using it, fewer than 100 suffered breaches, yet the fallout reached government agencies, a central bank and several universities. In February 2021, Five Eyes agencies issued a joint advisory on those attacks.
Attackers favor these systems for a simple reason. They store the sensitive documents an organization needs to move around, which makes them a natural target for data-theft extortion.
Unencrypted Records on a File-Sharing Server
Nothing in the letter, or in any report so far, says code ran on that server. What the letter does describe is a vulnerability and people reading files they shouldn’t have reached; that’s a data access failure, not a malware case.
So the more useful question is where the data was kept. We covered the Swiss federal IT agency breach, and it makes a handy comparison. Intruders there got into roughly 200 accounts, yet the agency’s own rules barred highly sensitive personal data from that SharePoint platform. The most damaging category of data simply wasn’t there to take. At DMDC, Social Security numbers for millions of people sat unencrypted on a server built for sharing files.
The letter is also revealing about what DMDC can and can’t prove. It knows whose records the intruders reached, and it has written to those people. Who the intruders were, it doesn’t know or won’t say. Meanwhile, the public figure moved from four million to just over three in four days. Federal agencies run their systems under FISMA, with NIST SP 800-137 describing the continuous monitoring they’re supposed to have; whatever monitoring covered this server took nine months to surface the access, if it surfaced it at all.
Logs can reconstruct an incident afterward. They can’t show that those files were out of reach in the first place, because only controls enforced before October 2025 could have done that.
Conclusion: The Flaw Opened the Files. Nothing Else Stopped It.
The DMDC breach demonstrates how a single access-control failure becomes a much larger incident when sensitive data has no meaningful second boundary behind it. A vulnerability in a file-sharing system allowed unauthorized users to reach files for roughly nine months. Those files contained unencrypted Social Security numbers and other personnel information tied to millions of people.
What remains unknown is as important as what has been disclosed. The Pentagon has not identified the file-sharing product, described the vulnerability, explained how the unauthorized users gained access, or said who they were. There is also no evidence in the public record that malware executed on the server. The confirmed failure is narrower: people who should not have been able to read the files were able to reach them.
The impact, however, extends beyond conventional identity theft. Names, Social Security numbers, contact information, and military occupational specialties can remain useful long after passwords or payment cards would have been replaced. For military personnel, combining identity with role information also creates profiling and targeting value that credit monitoring cannot address.
Why This Threat Matters
- The exposure lasted roughly nine months. Unauthorized access began in October 2025 and remained possible until the vulnerability was discovered in July 2026.
- The data was stored unencrypted. Once file access was obtained, there was no additional cryptographic barrier protecting the records.
- The affected information has a long shelf life. Social Security numbers, identity details, and military service information cannot simply be rotated.
- The risk extends beyond financial fraud. Occupational and personnel information can support profiling, targeted social engineering, and intelligence collection.
- Incident logs answer only part of the question. They may help reconstruct which files were reached, but they do not demonstrate that highly sensitive records were appropriately inaccessible before the breach.
Where Defensive Control Must Operate
Where valid identities or active sessions are involved, Xcitium ITDR provides a critical control layer by detecting abnormal access patterns, excessive data reach, suspicious privilege use, and activity that diverges from the legitimate user’s normal behavior. In an incident where millions of sensitive records were exposed, that identity-side visibility is essential for determining whether authorized credentials became the path to unauthorized access, even though the public reporting has not yet confirmed that mechanism here.
Reduce the Reach Before the Next Flaw
DMDC patched the discovered vulnerability, but remediation should also address why a compromised file-sharing path could reach unencrypted records at this scale. Review data placement, access entitlements, encryption, segmentation, and retention so that the next application failure exposes the smallest possible dataset rather than everything the service can reach.