It is reported that the U.S. government is notifying millions of current and former U.S. military personnel and staff members that their personal information was stolen during a months-long data breach at the Pentagon's personnel records system. This is the latest in a series of data theft incidents involving federal employees in recent months.
A data breach notification shared on Reddit from the National Defense Human Resources Data Center ( Defense Manpower Data Center, referred to as DMDC ) stated that over several months from October 2025 to mid-July 2026, multiple unauthorized users took advantage of a security vulnerability in an unspecified file sharing system.
This leak exposed personal identification information, including social security numbers, as well as names, dates of birth, genders, races, and other information related to their military service. The notification stated that these personnel records were not encrypted.
According to CNN and Federal News Network, a Pentagon official stated that this leak affected approximately 2.8 million living individuals, as well as nearly 300,000 deceased individuals.
As of March this year, the total number of active-duty military personnel in the U.S. Armed Forces is 1.3 million.
DMDC may not be well-known to the general public, but it is one of the agencies responsible for record-keeping at the U.S. Department of Defense. DMDC maintains records of over 60 million U.S. military personnel, civilian employees, and their families, which are used to determine benefits and rights such as medical care and retirement. The agency also provides a crucial service; as the "primary identity management provider" for the military, it links active-duty soldiers, employees, and contractors with credentials such as smart cards and passwords. These credentials are used to access computer systems, office buildings, and bases at the Pentagon.
DMDC The website states: "We ensure that the right people get access, while the wrong people do not; the security of identity information is of paramount importance."
The U.S. Department of Defense, which is responsible for regulating DMDC, stated that there are no signs that this information has been misused, but it did not provide any basis for reaching this conclusion. TechCrunch contacted a Pentagon spokesperson to inquire whether officials had received any communications from hackers; the identities of these hackers are still unclear at this time, but no response was received as of press time.
This is the latest major incident of personal information leakage involving federal employees in recent months. Earlier in September, there was also a leakage incident at the Federal Bureau of Investigation (FBI) in the United States, which is said to be related to a hacking group. The group told authorities that they obtained personal information on most of the FBI's agents and staff, including applicants for jobs. Given that foreign governments could potentially obtain and use this information to profile federal employees, target them, or coerce them into handing over sensitive data, this incident has been described as an "anti-intelligence disaster."
ShinyHunters Hackers stated that they will not publicly release the stolen FBI data.
The two incidents involving FBI and DMDC are in line with similar past cases of government personnel records being stolen. In 2015, the U.S. government's human resources department, namely the Office of Personnel Management (OPM), Office of Personnel Management OPM, experienced a data breach, which was widely attributed to China. As a result of that theft, hackers obtained the personal records of over 22 million U.S. government employees, many of whom held security clearance.
Have you received any notifications regarding this data breach? TechCrunch expresses a desire to hear about the situation. You can contact reporter Zack Whittaker through Signal, whose account is zackwhittaker.1337, or send an email to zack.whittaker @ techcrunch.com.











