Pentagon personnel breach exposes data of more than 3 million as FBI probes separate cyberattack
A breach of a Pentagon personnel database exposed sensitive information belonging to more than 3 million current and former military and civilian personnel, including Social Security numbers and details about their jobs, according to U.S. defense officials.
The breach affected about 2.76 million living individuals and 294,000 deceased people, a Defense Department official told ABC News. The exposed information included personally identifiable information as well as details concerning positions held by military and civilian personnel, raising potential national security concerns.
The affected system is operated by the Defense Manpower Data Center (DMDC), one of the Pentagon's main repositories for personnel information. The center maintains records on active-duty and reserve service members, civilian employees, contractors, retirees, veterans and military family members.
A Pentagon official said unauthorized users accessed personally identifiable information between October 2025 and July 2026. The DMDC discovered the vulnerability on July 16 and subsequently took steps to remediate it, according to a breach notification letter reviewed by Military Times.
"An information system experienced unauthorized access of personally identifiable information by a small number of unauthorized users between October 2025 and July 2026. Upon discovery, DMDC immediately remediated the vulnerability," the official said.
The DMDC holds more than 60 million personnel records, making the incident one of the more significant recent compromises involving U.S. military personnel data.
Officials said there is currently no evidence that the exposed information has been misused. The Defense Department is offering affected individuals identity-protection and credit-monitoring services.
The Pentagon breach comes amid a separate investigation by the Federal Bureau of Investigation into an alleged compromise involving its FBIJobs.gov recruitment portal.
The FBI said it is investigating claims by the cybercriminal group ShinyHunters that it compromised FBIJobs.gov and obtained personally identifiable information belonging to current and former employees and job applicants.
The bureau said it had not yet determined whether the breach originated within FBI systems or at a third-party provider supporting the jobs website. It said it was working with those providers to investigate the incident and mitigate potential risks.
ShinyHunters claimed it had obtained large quantities of sensitive information, including names, home addresses, telephone numbers, Social Security numbers, dates of birth, job assignments and family or emergency-contact information. Reuters reported that a sample allegedly containing information on about 5,000 FBI employees was partially verified through independent checks, although the exact source and full scope of the data remained unclear.
The FBI's recruitment portals were taken offline following the incident and remained unavailable as of Sept. 28, according to cybersecurity publication Help Net Security.
ShinyHunters has said the attack was not financially motivated. In a statement reported by several media outlets, the group said it was seeking to challenge an FBI warning issued earlier this year that characterized the group as a cybercriminal threat.
The group subsequently said it would not release the data it had threatened to publish, describing the operation as a campaign intended to defend its reputation and challenge what it called misinformation.
The FBI has not independently confirmed the group's claims about the full volume of data stolen or the extent of the alleged compromise.
The two incidents have raised concerns beyond conventional identity theft because the compromised information may reveal where military and law-enforcement personnel work and, in some cases, information about sensitive assignments.
Reporting on the alleged FBI breach found that some of the exposed records appeared to involve employees working in intelligence, surveillance and other sensitive areas.
Cybersecurity experts have warned that information such as home addresses, family details and work assignments can be exploited for harassment, targeting, social engineering or intelligence-gathering, even when the underlying systems do not contain classified information.
The FBI has said the compromised jobs portal was unclassified. However, the potential exposure of personal information belonging to employees working in sensitive positions has prompted the bureau to warn affected personnel to remain vigilant and avoid suspicious communications.
The developments also come as U.S. authorities continue to investigate a series of cyber incidents targeting government agencies and contractors.
In a separate development linked to the wider investigation into ShinyHunters, Dutch police arrested a 24-year-old cybersecurity professional in the Netherlands on Sept. 28. Reuters reported that the man had previously been convicted of cybercrime but later worked in cybersecurity. Authorities have not established that he was responsible for the FBI intrusion.
The Pentagon and FBI investigations remain ongoing, and authorities have yet to establish the full scope, origin and potential consequences of either incident. (ILKHA)
LEGAL WARNING: All rights of the published news, photos and videos are reserved by İlke Haber Ajansı Basın Yayın San. Trade A.Ş. Under no circumstances can all or part of the news, photos and videos be used without a written contract or subscription.
US President Donald Trump has proposed replacing the term “artificial intelligence” with “super intelligence,” saying the word “artificial” makes the technology sound less authentic than it is.
Sensitive components from the F-35 stealth fighter were unexpectedly diverted to Hong Kong while being shipped from Australia to the United States for repairs, with some of the parts subsequently reported missing, raising concerns in Washington over the possible exposure of highly sensitive military technology.
Geoffrey Hinton, the Nobel Prize-winning computer scientist widely known as the “Godfather of AI,” has warned U.S. lawmakers that they may have only about a year to establish meaningful safeguards for artificial intelligence before humans risk losing control over increasingly autonomous systems.