Thursday 1 October 2026 506 stories on file Full archive
Daily Edition
newscms

Volume III Edition Daily

Pentagon Personnel Breach Exposes 3 Million Records, and the Data Was Unencrypted

For roughly nine months, a small number of unauthorized users had access to an unencrypted file-sharing system operated by the Defense Manpower Data Center, the Pentagon's records-keeping and identity management arm…

Cybersecurity 1,768 words 9 min read

Pentagon Personnel Breach Exposes 3 Million Records, and the Data Was Unencrypted — Cybersecurity No Image Cybersecurity
Lead image · Filed 1 October 2026, 04:49

Pentagon Personnel Breach Exposes 3 Million Records, and the Data Was Unencrypted

Introduction

For roughly nine months, a small number of unauthorized users had access to an unencrypted file-sharing system operated by the Defense Manpower Data Center, the Pentagon's records-keeping and identity management arm. The agency has now begun notifying the people affected, and the number is larger than most disclosures of this kind: nearly 2.8 million living individuals and about 294,000 people who are deceased.

What was taken includes Social Security numbers, names, dates of birth, contact details, and information about military service. The Defense Manpower Data Center, or DMDC, is not a household name, but it is described in its own materials as the military's "leading identity management provider" — the organization that ties service members, employees and contractors to the smart cards and passwords used to reach Pentagon computer systems, buildings and bases. That makes this more than a large mailing-list leak. It is a compromise of the system of record that underwrites who is allowed through the gates of the largest security apparatus in the United States.

The disclosure arrives in the middle of a concentrated run of attacks on government systems, and it lands in the same week that a cryptocurrency exchange lost roughly $388 million through a vulnerability in a third-party security product. The common thread is not sophistication. It is ordinary infrastructure — a file-sharing platform, a security appliance, a graphics framework — being reached by people who knew where to push.

Nine Months of Undetected Access

According to a notice from DMDC shared publicly and quoted by TechCrunch, several unauthorized users exploited a security vulnerability in an unspecified file-sharing system over a period running from October 2025 to mid-July 2026. A Pentagon official told Federal News Network that a small number of unauthorized users had access for nearly a year. A notice sent to one affected person states that the vulnerability was discovered on July 16 and patched immediately.

The same reporting notes that the records were unencrypted, and that the type of data exposed varies from person to person. One Pentagon official declined to answer several questions, including why personal information was being held on an unencrypted server in the first place.

The timeline is the part that should worry defenders more than the file count. Nine months of undetected access means the attackers had a long window to identify, select and extract whatever they wanted, without the urgency that a short intrusion imposes. There is no indication the Department of Defense has evidence the data was misused, and the agency has said it is taking steps to assess and enhance the cybersecurity posture of the system. It has also hired IDX, a breach recovery firm, to provide 12 months of credit monitoring to those affected. Credit monitoring addresses the financial-identity half of the problem. It does not address the targeting half.

Why an Identity Breach in This System Matters More

DMDC maintains records for more than 60 million troops and veterans, current and former civilian employees, contractors and family members. Those records exist to determine benefits and entitlements — healthcare, retirement, and the administrative machinery that supports them. The same data set authenticates credentials. As the organization's own site puts it, the job is to make sure the right people get access and the wrong people do not.

That dual role is what separates this incident from a run-of-the-mill records exposure. A name and a Social Security number are useful for identity theft. The same name and number, attached to a verified job specialty and a confirmed affiliation with the Department of Defense, are useful for something else. They let an adversary build a list of people whose roles make them worth cultivating, approaching, or coercing, and to do it with a confidence that a leaked password list cannot provide. The 2015 breach of the Office of Personnel Management, which broadly attributed to China, exposed records of more than 22 million US government employees and is still the reference point for how serious a federal personnel compromise can get.

The FBI's experience this month is the closer parallel. The ShinyHunters ransomware group claimed it breached the FBI's job application portal, FBIJobs.gov, and stole data on thousands of agents and applicants, including some staff. The FBI issued an internal notification confirming that names, addresses, job titles and Social Security numbers were exposed, and reportedly declared a "major incident." Unusually, the hackers are not seeking money. They are demanding the FBI correct a report they say misrepresents their activities. In other words, the incentive here is reputational and informational, not financial — which is a reminder that a breach of a government agency can be a propaganda operation rather than a smash-and-grab.

The FBI exposure drew a specific kind of attention in the New York Times, which framed it as an embarrassment that could fuel fears about the safety of the bureau's own employees. The DMDC breach raises the parallel question at a larger scale, with about six times as many living people in the notification population.

The Same Week, A Different Kind of Lesson

Elsewhere in the same week, the cryptocurrency exchange Bitget disclosed that attackers had taken approximately $388 million by exploiting a zero-day vulnerability in a third-party security product the exchange used. According to The Hacker News, the flaw gave an attacker access to an internal management system, from which fraudulent withdrawal commands were inserted into wallet-related backend services where they were treated as legitimate. The exchange described the flaw as a zero-day, meaning it was exploited before a fix existed.

Several details from that incident are worth borrowing as lessons. Bitget's CEO said the attacker used legitimate credentials and disguised activity as routine administrative operations while removing traces. The first movement was two small test transfers at 18:31 UTC on September 24 that stayed below the exchange's risk-control threshold and raised no alert. The larger transfers followed about 30 minutes later and executed anyway. A critical backend system had also been used to spoof transaction data and trigger the approval process itself — so the human sign-off that should have caught a fraudulent withdrawal was satisfied by forged inputs rather than by an attacker's guesswork.

Cold wallets were not touched and no private keys were compromised, according to the exchange's investigation so far. Customer balances were unaffected, and a protection fund set aside for incidents like this one will cover the loss. Mandiant and SlowMist are supporting the investigation, and TRM Labs reported overlaps between the stolen funds and wallets used to launder earlier North Korean thefts, pointing toward the group known as TraderTraitor without a firm public attribution.

The pattern worth noticing is that the money did not come from breaking the crypto. It came from a security product. An organization can be rigorous about key management and still be walked through the side door by a vendor's unpatched appliance.

The Vendor Problem Has No Clean Edges

Apple shipped its own reminder in the same window. On September 28 it released emergency security updates for CVE-2026-86950, an out-of-bounds write in the CoreGraphics framework that can lead to arbitrary code execution when a device processes a crafted file, according to SOC Prime's analysis. The fix shipped as iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1; the newer iOS 27 and macOS Golden Gate 27 branches do not appear to be affected.

Apple says it is aware of a report that the flaw may have been used in an "extremely sophisticated attack" against specific targeted individuals running versions of iOS earlier than iOS 27. Meta Product Security reported the vulnerability. Apple has not disclosed the delivery mechanism, the targets, or whether exploitation succeeded, and has published no indicators of compromise and no proof of concept. As of September 29, CISA had not added it to the Known Exploited Vulnerabilities catalog.

What CoreGraphics illustrates is breadth of reach. It is used to render two-dimensional content and PDF documents across Apple's platforms, which means a file-processing path can be reached from a web page, an email attachment, a messaging app, or a document preview. Automatic previews are precisely the feature that makes a parser dangerous: content can be processed before a human chooses to open anything.

What Defenders Should Take From This

The DMDC case is a reminder that the most consequential breaches often involve a mundane component rather than a sophisticated adversary. A file-sharing system with a vulnerability. A security appliance with a zero-day. A graphics parser reachable by a thumbnail. None of these require exotic capability; they require a target that has not patched for a while and does not have good visibility into who is using the system.

Three practices follow. First, encryption at rest is not optional for a system holding identity data at this scale, and the fact that these files were unencrypted converts a compromise from an authentication problem into a disclosure problem. Second, monitoring internal management systems matters more than perimeter controls, because in both the Bitget case and the personnel-record cases, the attacker operated with credentials that looked legitimate. Third, detection lag is a metric in its own right. Nine months is not a near miss; it is the actual duration of the intrusion.

None of that changes the immediate situation for the millions of people who received a notice. For them, the practical advice is unglamorous. Treat the notice as real, enroll in the credit monitoring being offered, be skeptical of unsolicited contact referencing military or federal employment, and assume that a Social Security number linked to a verified role in the Defense Department is worth more to a criminal than a random one.

Images

Aerial view of the Pentagon, headquarters of the US Department of Defense, in Arlington, Virginia

The Pentagon, headquarters of the Department of Defense, which oversees the Defense Manpower Data Center whose information system was breached.

A US Navy officer works at a workstation handling an identification card

US Navy personnel handling identification credentials. DMDC serves as the identity management provider that links service members and staff to the cards and credentials used to access military systems and facilities.

A Trezor One hardware cryptocurrency wallet beside a physical Bitcoin token

A hardware wallet and physical Bitcoin token, illustrative of the crypto assets at stake in the separate Bitget theft of roughly $388 million this week.

References

Related coverage on our cybersecurity desk tracks the continuing wave of attacks on government identity systems and on the third-party security products that guard critical infrastructure.