A major security flaw at a Pentagon defense agency exposed the private records and Social Security numbers of over 3 million people for months.
A major cybersecurity breach involving a key defense agency inside the United States Department of Defense has exposed the private personal information of more than three million military personnel, retirees, and their families.
Official updates released on September 29, 2026, confirmed that a security flaw inside a files haring system used by the Defense Manpower Data Center allowed unauthorized computer users to view unencrypted personal files stored on official defense servers for nearly nine months.
The affected population includes roughly 2.8 million living service members and family dependents, alongside nearly 294,000 deceased former defense personnel.
The serious security incident centered on an official database system that manages crucial manpower, healthcare, and training records for tens of millions of military members and government workers across the country.
According to notification letters sent out to affected victims, computer safety teams first discovered the software flaw on July 16, 2026.
Subsequent forensic investigations revealed that unknown intruders had been quietly accessing sensitive personal files on the affected file sharing server starting all the way back in October 2025.
The exposed information includes highly sensitive identifying details that could put affected service members at risk of identity theft or targeted fraud.
Leaked files contained full government Social Security numbers along with names, dates of birth, private contact details, demographic records, and specific military job classification codes.
Because the affected files were stored on the server without proper encryption protection, unauthorized users were able to view the raw personal details directly without needing special decryption keys.
Detailing how the security failure occurred inside the system, official notification letters sent to victims explained that “a security vulnerability in a DMDC file-sharing system was discovered, which allowed unauthorized users to access files.”
The agency reassured affected individuals by noting that “DMDC immediately updated the file-sharing system to patch the vulnerability, and the system was restored”.
Defense officials further added that “a small number of unauthorized users” had been accessing files on the server before the flaw was found and closed.
See Also: Bad AI Prompt Causes First AI-Related Data Leak in Singapore
In response to the major privacy incident, defense officials initiated standard incident-response procedures to lock down affected servers and prevent further unauthorized access.
Defense representatives confirmed that there is currently no evidence indicating that the stolen personal information has been published online or misused by criminal hackers.
However, safety experts advise affected service members and veterans to keep a close eye on their credit reports and watch out for suspicious telephone calls or phishing messages trying to trick them into giving away more personal data.
As government agencies review how the software bug went unnoticed for so many months, computer security researchers emphasize the critical need to encrypt all sensitive records stored on connected networks.
With official notification letters now reaching millions of military households, defense leaders promise to strengthen their digital guardrails to keep confidential personal information safe from future online intrusions.

