Millions face identity risk after Pentagon personnel breach

Millions face identity risk after Pentagon personnel breach. Millions of current and former defense personnel and their dependents now face long-term identity risk after unauthorized users accessed Pentagon personnel files.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, October 2nd, 2026.

Millions of current and former defense personnel and their dependents now face long-term identity risk after unauthorized users accessed Pentagon personnel files. The Defense Manpower Data Center says the breach affects 2.76 million living people and two hundred ninety four thousand deceased individuals. Access continued from October 2025 until the issue was discovered on July 16th, 2026, and involved a vulnerability in a file-sharing system.

The exposed information varied by person. It included names, Social Security numbers, birth dates, contact details, race, sex and military job specialties. The records were unencrypted, which makes this kind of exposure difficult to reverse. The department says it has no indication of misuse, but it hasn’t said whether the files were copied.

Personnel systems and file-sharing platforms need to be treated as high-value infrastructure rather than back-office tools. Defenders should review access logs, encryption coverage and data-retention choices across similar repositories. Organizations should notify affected people promptly, strengthen file-sharing controls and monitor exposed identities for fraud. The larger lesson is that one weakness in a centralized identity store can create years of risk for individuals.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Millions face identity risk after Pentagon personnel breach
Broadcast by