The U.S. Department of Defense has acknowledged a massive data breach of its property. The incident involved an information system of the Defense Manpower Data Center (DMDC) and has resulted in the exposure of confidential personal information of more than 3 million people.
The intrusion would involve the compromise of data relating to 2.76 million living individuals and about 294,000 deceased individuals. Among the exposed details are Social Security Numbers (SSN), personally identifiable information identifying military and civilian personnel, as well as military occupational information (data on functions, ranks, positions, or specialties assigned to each member of the personnel in their positions within the Armed Forces).
Unauthorized access to the Pentagon occurred between October of last year and July of this year, according to the investigation. During this interval, threat actors were able to roam freely through the system.
The entry occurred through a security vulnerability detected in a file-sharing system, which allowed the attackers to enter and access confidential files hosted on the affected server.
Following the confirmation of the incident, senior U.S. defense and cybersecurity officials have stated that immediate measures have been implemented to patch the software vulnerability used in the attack and to strengthen the access protocols to personnel data.
“There is currently no evidence that the exposed information has been misused,” a Pentagon spokesperson noted.
Additionally, a notification process has been initiated for the affected individuals, and the Department of Defense is actively collaborating with cybersecurity agencies to determine the full extent and potential culprits of the cyberattack. For now, their names have not been disclosed.
Beware of cybercriminals… and journalists
According to internal security warnings described by government agencies and disseminated by networks like ABC News, affected personnel were expressly instructed “not to speak with the media,” remain alert to suspicious calls, and “immediately call 911 if journalists are committing trespassing or intrusion on private property.”
Unauthorized access to this type of professional and military information is especially critical, as the combination of Social Security Numbers with each military’s occupational profile could be exploited by threat actors to conduct targeted social engineering (spear-phishing), target profiling, or identity theft attempts.

