The US Department of Defence disclosed a breach of a file-sharing system operated by the Defence Manpower Data Centre that allowed a small number of unauthorised users to access sensitive, unencrypted personal information for about nine months. The incident affected more than 3 million records, while the department did not identify who was behind the access or their motives.
Discovery of the vulnerability and repair of the sharing system
According to a notice the centre sent to affected people on 24 September 2026, the security vulnerability was discovered on 16 July of the same year. An investigation following its discovery found that the unauthorised access began in October 2025 and continued until July 2026. The Department of Defence said the vulnerability was addressed immediately after it was discovered, before the system was restarted once the repairs had been completed.
The Defence Manpower Data Centre is one of the main repositories of data on personnel in the US military organisation, holding records relating to multiple groups connected to the Department of Defence and their families. Available information about the incident indicates that the entry point was a vulnerability in a file-sharing system operated by the centre.
The flaw enabled access to files stored on a server containing unencrypted personal data, making their contents viewable to users who managed to enter the system. The Department of Defence did not disclose technical details of the vulnerability or the method used to exploit it. It also did not establish whether the incident was a conventional cyber-attack, the exploitation of a misconfigured security setting or the result of another access mechanism.
Available identity and military service data
The department said the investigation identified a small number of unauthorised users, without providing further information about their identities or motives. The files included Social Security numbers and a range of identifying information that varied from person to person.
The information included names, dates of birth, contact details, sex and race, as well as military service information, including the specialism or military job held by the individual concerned. Media reports confirmed that the data in the files was not encrypted.
The incident is particularly sensitive because some records combine Social Security numbers with other identifying information that could be used to identify the people concerned, while some of the information is linked to service in the military organisation.
Distribution of affected records among department personnel and their families
A Department of Defence official said the breach affected 2.76 million living people, in addition to about 294,000 deceased people, bringing the total to more than 3 million records. The centre’s database includes current and former military personnel, civilian employees, contractors, retirees, veterans and their family members.
The Defence Manpower Data Centre holds more than 60 million records linked to Department of Defence personnel and their families, but the department has not said that all of these records were accessed without authorisation. Unofficial estimates put the potential number of affected people at about 4 million, but the Department of Defence has not confirmed this estimate.
The continuation of access from October 2025 until the vulnerability was discovered in July 2026 is one of the incident’s most significant aspects. The department has not provided a detailed explanation of why the activity was not detected earlier, clarified the monitoring system applied to the file-sharing system or explained why no alert was issued during the months in which access continued.
The published information does not establish whether there was a specific failure in detection or monitoring systems, as reaching such a conclusion would require additional technical evidence. It is also unclear whether the unauthorised users merely viewed the files or copied all the data they were able to access during the period in question.
The Department of Defence said it currently had no indications that the accessed information had been misused. The department has begun notifying affected people and has offered them one year of credit-monitoring and identity-restoration services, according to the breach notice reviewed by Military Times.
The sensitivity of the files is not limited to their personal information, as they are also linked to the identities of army personnel and Department of Defence employees, their specialisms and their employment relationships.
The continuation of unauthorised access for months places the protection of file-sharing systems, data encryption and mechanisms for detecting unusual behaviour within large-scale government databases at the centre of the incident’s technical implications.