Natalie Oliverio, a Navy veteran who covers military and veterans' issues, reported that a Pentagon data breach involving military personnel exposed unencrypted personal information in a Defense Manpower Data Center file-sharing system. Two people familiar with the incident said about four million Defense Department personnel may be affected.
The notice sent on Sept. 18 said the affected person's information was in the files. The Defense Department is offering one year of credit monitoring and identity-restoration services through IDX.
Defense Manpower Data Center files
The vulnerability let unauthorized users access files on a server containing unencrypted personally identifiable information between October 2025 and July 16, 2026. The exposed material included Social Security numbers and at least one additional identifier, such as a name, date of birth, contact information, sex, race or military personnel information.
DMDC discovered the vulnerability on July 16 in a file-sharing system and then updated the system to patch it and restored it. DMDC says it serves as the Defense Department's central source for identifying, authenticating, authorizing and providing information on personnel during and after their affiliation with the department, and its website says it maintains more than 60 million DoD records.
Security vulnerability notice
The notification letter said the security vulnerability allowed unauthorized users to gain access to the files, including the recipient's Social Security number. It also said the department had no indication that the individual's information had been misused.
That leaves affected personnel with a practical next step: use the one year of credit monitoring and identity-restoration services if they receive the notice, because the exposed data already included the kind of identifiers that can be used to open accounts or verify identity. The unanswered question is how many people were actually affected and who accessed the files.
Military Times report
Military Times reported the scope after speaking with two people familiar with the incident. Oliverio's reporting puts the breach in the context of a records system built to hold personnel information on a very large scale, which is why the access to unencrypted files matters to anyone whose data may have been included.







