Back to Home
Technology

Pentagon database breach exposes sensitive information on nearly 3 million people

An unauthorised intrusion into a system belonging to the Pentagon’s Manpower Data Centre exposed information on 2.76 million living people and 294,000 deceased people. The data included Social Security numbers and employment records, while defence officials said they had so far found no evidence that it had been misused.

••3 min

Listen to this article

An automatically generated audio version.

0:00
0:00
A photograph of the U.S. Department of Defense emblem featuring a model of the Pentagon and the words “THE PENTAGON WASHINGTON” against a blue and red illuminated background.

A huge database belonging to the US War Department (the Pentagon) was hit by a security breach that exposed sensitive information on nearly 3 million military personnel and department employees, US network ABC News reported on Tuesday, citing US defence officials.

Data on 2.76 million people compromised

An official told the network that the system had been subject to unauthorised access to personally identifiable information between October 2025 and July 2026. The exposed data included Social Security numbers, as well as information about jobs held by military personnel and civilian employees. The defence official said the nature of the compromised data could raise national security concerns.

He added that a limited number of unauthorised users had managed to access the information, stressing that the Manpower Data Centre fixed the security vulnerability as soon as it was discovered. Defence officials have so far found no evidence that the information exposed in the incident was misused, ABC News reported.

Other breaches target US security institutions

The disclosure of the Pentagon data breach came as other incidents targeting the systems and data of US security institutions were being investigated. In a separate incident days earlier, a hacker group called ShinyHunters claimed it had breached the FBI’s jobs portal.

The group claimed to have obtained the names of former agents and job applicants, along with home addresses, telephone numbers, the names of spouses and some medical information, according to The New York Times. The FBI acknowledged the hacking claims and launched an investigation. The bureau said the point of compromise had not yet been determined, and it was also unclear whether the incident occurred at an external provider or within the bureau’s own systems.

The alleged breach is the latest in a series of incidents affecting the bureau’s cyber infrastructure. Authorities previously discovered Chinese hackers inside a database linked to domestic surveillance orders, following breaches of US telecommunications networks. Personal emails belonging to FBI Director Kash Patel were also hacked and leaked last March in an attack attributed to a pro-Iranian activist group.

ShinyHunters said it had exploited a zero-day vulnerability in Oracle PeopleSoft, which is used to manage human resources and financial data. The group claimed that it had seized between 2 and 3 terabytes of data in the breach.