Hackers stole records of 2.8 million U.S. military personnel, and the data wasn’t even encrypted

The Pentagon kept records on tens of millions of military personnel without encrypting them. That single fact should stop you cold. Because when hackers exploited a vulnerability in a Defense Department file-sharing system sometime between October 2025 and mid-July 2026, there was nothing standing between the attackers and some of the most sensitive personal data the U.S. government holds.

According to TechCrunch, the breach hit the Defense Manpower Data Center, a Pentagon records unit most people have never heard of but probably should know about. The DMDC maintains over 60 million records covering active service members, civilian staff, contractors, and their families. It also acts as the military’s primary identity management system, linking personnel to smart cards and passwords used to access Pentagon buildings, bases, and computer systems. In short, it’s the gatekeeper. And someone got in.

The stolen data includes Social Security numbers, names, dates of birth, sex, race, and details about individuals’ military service. About 2.8 million living people are affected, along with roughly 300,000 deceased individuals. For context, the U.S. military has approximately 1.3 million active service members. This breach reaches far beyond current troops.

The Department of Defense says it has no indication the stolen data has been misused. But it didn’t explain how it arrived at that conclusion, which is a convenient non-answer. The identities of the hackers remain unknown. A Pentagon spokesperson confirmed the number of affected individuals but declined to answer basic questions about the incident, including whether officials had received any communications from whoever carried this out.

This is not an isolated incident. It fits into a pattern that should alarm anyone paying attention. Earlier in September, the ShinyHunters hacking group breached the FBI, taking personal data on agents, staffers, and applicants. That breach was called a counterintelligence disaster because foreign governments could use that kind of data to identify, profile, and pressure federal workers into cooperation. The DMDC breach carries similar risks, possibly worse given the scale and the identity management role the center plays.

The historical parallel is impossible to ignore. In 2015, hackers widely attributed to China broke into the Office of Personnel Management and stole records on more than 22 million government employees, many with security clearances. That breach reshaped how intelligence agencies think about personnel data. A decade later, these same categories of data are still being lost, still unencrypted, still managed by systems with exploitable vulnerabilities that go undetected for months.

So what does this mean for the people affected? Their Social Security numbers are now potentially in the hands of unknown actors. Combined with service history and identity credentials, that data is a toolkit for fraud, coercion, and targeted attacks. The government’s reassurance that it sees no signs of misuse offers little comfort when the breach went undetected for nine months in the first place.