Pentagon and FBI Report Breaches Exposing Millions of Personnel Records

OpenAI Pentagon surveillance protections

Pentagon and FBI report breaches exposing millions of personnel records: a DMDC hack affects ~3 million people with SSNs and job details, while the FBI probes a jobs portal breach claimed by ShinyHunters.

Pentagon and FBI report breaches exposing millions of personnel records

Pentagon and FBI report breaches exposing millions of personnel records in two separate incidents disclosed in late September 2026. A vulnerability in the Pentagon’s Defense Manpower Data Center (DMDC) allowed unauthorised access to personally identifiable information—including Social Security numbers and job details—for roughly 3 million people, while the FBI is investigating a breach of its recruitment portal, FBIJobs.gov, in which hackers claim to have stolen employee data.

The disclosures come amid heightened concern over foreign intelligence targeting of US defence and law‑enforcement personnel, with experts warning that exposed records could be used for identity theft, spear‑phishing, blackmail, and counterintelligence operations.

Pentagon DMDC breach: what was exposed

The Pentagon breach involves the Defense Manpower Data Center (DMDC), one of the Department of Defense’s main personnel repositories. According to a defence official and breach notification letters:

Timeframe: Unauthorised access occurred between October 2025 and July 2026, when the vulnerability was discovered and patched.

Scope: The breach affected approximately:

  • 2.76 million living individuals, and
  • 294,000 deceased individuals.
    Some reports estimate up to 4 million current and former DoD personnel may be impacted.

Data exposed: Files contained unencrypted personally identifiable information (PII), including:

  • Names and Social Security numbers.
  • Dates of birth, contact details, sex, race, and demographic information.
  • Military personnel data, such as occupational specialties and job details.

DMDC maintains more than 60 million personnel records covering active‑duty and reserve troops, civilian employees, contractors, retirees, veterans, and military family members. The compromised server held a subset of these records.

Response and risk assessment

Defence officials say:

  • A small number of unauthorised users accessed the system.
  • There is no evidence so far that the exposed data has been misused.
  • Affected individuals are being offered identity protection and credit monitoring resources.

However, national security experts warn that the combination of SSNs and job/role information could help adversaries:

  • Build targeted spear‑phishing campaigns against service members.
  • Attempt identity theft and financial fraud.
  • Conduct blackmail or coercion operations, especially against personnel in sensitive roles.

FBI jobs portal breach: what is known

Separately, the FBI notified employees about a breach involving its recruitment website, FBIJobs.gov. Details remain limited, but multiple reports indicate:

A threat actor claimed to have obtained information including:

  • Names, home addresses, and contact details (personal and work).
  • Social Security numbers, dates of birth, and emergency contact information.

The breach was disclosed in a notice sent to employees, with the FBI saying it is investigating the incident.

In a related development, the hacking group ShinyHunters claimed responsibility for breaching the FBI and said it stole psychiatric and medical evaluation records of FBI staff. Reuters reviewed documents consistent with those claims, though the FBI has not publicly confirmed the full scope of medical data exposure.

Why these breaches matter

Together, the Pentagon and FBI incidents highlight systemic risks in federal personnel systems:

  • Large, centralised databases like DMDC are high‑value targets for foreign intelligence and criminal groups.
  • Unencrypted PII combined with role and job details significantly raises the risk of targeted attacks on defence and law‑enforcement communities.
  • Breaches at agencies such as the FBI and DoD can have counterintelligence implications, not just financial or privacy harms.

The Pentagon breach also echoes earlier large‑scale federal data incidents, such as the 2015 OPM hacks that exposed data on more than 20 million current and former federal employees and applicants.

What affected individuals should do

For people notified of the Pentagon DMDC breach or the FBI jobs portal incident, recommended steps typically include:

  • Enrol in the offered credit monitoring and identity protection services.
  • Place fraud alerts or credit freezes with major credit bureaus.
  • Monitor financial accounts and credit reports for unusual activity.
  • Be alert to phishing attempts referencing military service, FBI employment, or personal details from the breach.
  • Use strong, unique passwords and enable multi‑factor authentication on key accounts.

Summary: Pentagon and FBI report breaches exposing millions of personnel records: a DMDC vulnerability allowed unauthorised access to SSNs and job data for ~3 million people between October 2025 and July 2026, while the FBI investigates a jobs portal breach in which hackers claim to have stolen employee PII and medical records.

Read Previous

Meta Goes All‑In on Muse: Mac App Control, Shopping, and a Dedicated Email Address