Unencrypted files on a Defense Department file-sharing system sat open to unauthorized users for roughly nine months, and the Pentagon now counts 2.76 million living people whose Social Security numbers were exposed as a result. The Defense Manpower Data Center, the department’s personnel-records hub, began mailing notification letters dated Sept. 18, 2026. Another 294,000 deceased individuals were swept in, which puts the combined total at about 3 million.
The 2.76 million figure did not come from the letters, which give no total. A Department of War official supplied it to CNN, and every other count in circulation traces back to that one unnamed source.
A File-Sharing Flaw Open From October 2025 to July 2026
According to the notice, a security vulnerability in a DMDC file-sharing system allowed unauthorized access to files between October 2025 and July 16, 2026, the day DMDC found the problem. The affected server held unencrypted personally identifiable information. DMDC patched the system and restored it, and the letter says the center “immediately initiated privacy and cybersecurity incident response actions.” No known cybercrime group has claimed the intrusion.
A Pentagon official told Federal News Network on Sept. 28 that a “small number of unauthorized users” had access. The same official, who was not named, declined to say who those users were, whether the access was intentional, or why the data was stored on an unencrypted server. Reporter Rachel S. Cohen wrote that the official put the living count at about 2.8 million, alongside the 294,000 deceased individuals.
The first public sign was not an announcement. Recipients photographed their letters and posted them online, including in a thread on the r/AirForce forum, and reporters then reached defense officials to confirm the notices were real. Military Times dated the letter it examined Sept. 18 and published on Sept. 24, so the story surfaced six days after the date on the letter and more than two months after DMDC found the flaw.
Social Security Numbers Paired With Birth Dates and Job Codes
Military Times obtained a letter that two defense officials confirmed as authentic, and it reported that the exposed data was a Social Security number plus at least one other identifier: a name, date of birth, contact details, sex, race or military personnel information such as occupational specialty. The mix differed from person to person, so the 2.76 million is a count of affected living individuals, and not every record carried every field.
DMDC says it maintains more than 60 million Defense Department records covering troops, veterans, civilian employees, contractors and family members. Privacy Guides cautioned that nothing suggests all of those 60 million were touched. Military Times separately heard from two people familiar with the incident that as many as 4 million personnel could be involved, a number the department has not confirmed.
The center also oversees identity verification for every Defense Department ID card holder, and Federal News Network recalled that on Sept. 3 a Pentagon official said an earlier problem with troops missing the documents needed for Common Access Cards showed no sign of foul play or of a data breach. The two matters have not been linked by the department.
Help Net Security framed the incident as the second blow to federal agencies within weeks, after the ShinyHunters extortion group claimed it had stolen personal information of FBI employees. The Pentagon letters carry no such claim from any group.
IDX’s Year of Protection and the FTC’s Freeze Option
DMDC is offering one year of free protection through IDX, the breach-response firm the department contracted, according to Help Net Security’s reading of the letters. Those letters say the department “does not have any indications of misuse of the accessed information.” Malwarebytes researcher Pieter Arntz pointed out that the Pentagon has not explained how it reached that conclusion or what it counts as misuse, and has not ruled out misuse later.
For a Social Security number, a year of alerts covers only a slice of the exposure, because the number does not expire. The Federal Trade Commission explains that under a freeze, nobody can open a new credit account in the person’s name, that placing or lifting one costs nothing, and that an initial fraud alert lasts one year and can be renewed. A freeze must be requested at all three credit bureaus, while a fraud alert goes through just one, which then notifies the other two.
The timeline in the letters is the part that stays fixed: access began in October 2025, DMDC caught it July 16, 2026, and the first notices are dated Sept. 18. DMDC has described only its own cleanup, promising “appropriate actions to assess and enhance the cybersecurity posture of the DMDC system,” and the department has named no one responsible.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Ford is recalling 223,472 F-150 pickups because the fuel tank can leak or detach
- Hybrids have 15% fewer problems than gas cars, while EVs and plug-in hybrids have about 80% more, Consumer Reports finds
- Regulators cleared the first U.S. small modular reactor, 4 months early
- Lake Powell sank to a record 3,517 feet, nearing the level that stops Glen Canyon Dam’s turbines