Pentagon breach exposes long-lived identity data for millions

Pentagon breach exposes long-lived identity data for millions. Millions of people face continuing identity and impersonation risk after unauthorized users accessed a Defense Manpower Data Center system.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, October 5th, 2026.

Millions of people face continuing identity and impersonation risk after unauthorized users accessed a Defense Manpower Data Center system. The incident affected 2.76 million living people and approximately two hundred ninety four thousand deceased individuals. Access reportedly continued from October 2025 until July 2026 through a file-sharing weakness. The exposed records were unencrypted and could include Social Security numbers, birth dates, contact details, demographic data, and military occupational information.

The Pentagon has reported no evidence that the information has been misused. Affected people are being offered one year of credit monitoring and identity-restoration services. But the exposed fields can retain value for years.

For leaders, short-term support doesn’t remove the continuing risk of fraud, phishing, impersonation, and counterintelligence activity. For defenders, file-sharing systems that hold bulk personnel data need strong access controls, encryption, logging, and exposure review. The larger lesson is that durable identity data creates a risk window far longer than the intrusion itself. Treat these personnel records as a long-term identity risk and maintain monitoring beyond the offered support period.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Pentagon breach exposes long-lived identity data for millions
Broadcast by