A months-long breach of the Defense Manpower Data Center exposed personal information belonging to roughly 2.8 million living current and former U.S. military personnel and staff, plus records for nearly 300,000 deceased people. Attackers reportedly exploited a file-sharing vulnerability between October 2025 and July 2026, accessing unencrypted records that included Social Security numbers, dates of birth, demographic information, and military service details. TechCrunch reports: The DMDC may not be widely known to the general public, but serves as one of the Department of Defense's records-keeping units. The DMDC maintains over 60 million records for U.S. military and civilian staff and their family members to help determine benefits and entitlements, such as healthcare and retirement. The unit also provides a critical service as the military's "leading identity management provider," which links active service members, employees, and contractors to credentials, such as smart cards and passwords. These are used to access Pentagon computer systems, buildings, and bases.
"We make sure that the right people get access and the wrong people don't: security of identity information is paramount," the DMDC's website reads. The Department of Defense, which oversees the DMDC, said it does not have any indication that the information was misused, but did not say how it reached that conclusion. TechCrunch contacted a Pentagon spokesperson to ask if officials had any communications from the hackers, whose identities are not known, but we did not hear back.
Read more of this story at Slashdot.