CTIPilot

Pentagon Defense Manpower Data Center (DMDC) personnel-data breach

incident · incident:pentagon-dmdc-military-personnel-breach-2026-09

Unauthorized users accessed an unencrypted DMDC file-sharing server between October 2025 and July 2026, exposing Social Security numbers and other PII of DoD military/civilian personnel; up to ~4 million people potentially affected, no attacker or mechanism disclosed (Military Times / CNN, 2026-09-24/25).

Aliases: DMDC breach, Pentagon HR breach 2026

Coverage timeline
1
first 2026-09-27 → last 2026-09-27
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-09-27/pentagon-dmdc-military-personnel-data-breach-unencrypted-ssn · ATT&CK page ↗

Story timeline

  1. 2026-09-27Unauthorized users had nine months of unencrypted access to a Pentagon HR file-sharing server; up to 4 million Defense Department personnel's Social Security numbers potentially exposed
    active-threatsA vulnerable Pentagon HR file server sat unencrypted and reachable for nine months before anyone noticed

Where this entity is cited

  • active-threats1

Source distribution

  • cnn.com1 (33%)
  • databreaches.net1 (33%)
  • militarytimes.com1 (33%)

explore in graph

Entries about Pentagon Defense Manpower Data Center (DMDC) personnel-data breach (1)

2026-09-27 · view entry permalink →

HIGHNATOB1

Unauthorized users had nine months of unencrypted access to a Pentagon HR file-sharing server; up to 4 million Defense Department personnel's Social Security numbers potentially exposed

A breach-notification letter dated September 2026 and sent 18 September to affected individuals, reviewed independently by both Military Times and CNN and confirmed authentic by two defense officials, discloses that unauthorized users accessed a vulnerable file-sharing server operated by the Defense Manpower Data Center (DMDC) (Military Times, 2026-09-24). DMDC describes itself as the Pentagon's central source for identifying, authenticating, authorizing and providing information on personnel during and after their affiliation with the department, and its own website says it maintains more than 60 million records on military and civilian personnel, contractors, family members, retirees and veterans (Military Times, 2026-09-24). Access to the server ran from October 2025 through 16 July 2026, roughly nine months, before DMDC discovered what the notification letter calls a "security vulnerability," patched it and restored the system; neither the letter nor either outlet names a CVE, exploit class, or states whether the server was reachable from outside DMDC's own network (Military Times, 2026-09-24).

Data taken from each affected individual's own record included an unencrypted Social Security number plus at least one further identifying field: name, date of birth, contact information, sex, race, or military-personnel and occupational-specialty data (Military Times, 2026-09-24). "The stolen data wasn’t encrypted, according to the letter" (CNN, 2026-09-25) despite that being, in CNN's framing, standard security practice for data of this sensitivity. DoD states it has no indication the data has been misused and is offering affected individuals one year of credit monitoring and identity-restoration services through contractor IDX. The full scope remains unconfirmed by DoD directly; two people familiar with the incident told Military Times that approximately four million Department of Defense personnel may be affected (Military Times, 2026-09-24).

CNN frames the exposure as a counterintelligence concern, not only a fraud one: combined with other datasets using identifiers like Social Security numbers, the accessed occupational-specialty data could give foreign adversaries a clearer read on who does what for the US military in various parts of the world (CNN, 2026-09-25). A bad actor could pair the DMDC data with other commercial datasets to “learn about or even target [defense personnel] based on their earnings, debts, marriages, spending habits, browsing activities, and worse,” according to Justin Sherman, CEO of Global Cyber Strategies (CNN, 2026-09-25). No party has publicly named who was behind the intrusion.

“Unauthorized users” gained access to a vulnerable computer server belonging to the Defense Manpower Data Center (DMDC) beginning last October, but it wasn’t until nine months later, in July, that the Pentagon discovered and remediated the issue, according to a letter the center sent to victims of the breach reviewed by CNN.

CNN 2026-09-25

The unauthorized users gained access to the Social Security number of the letter’s recipient, as well as at least one additional piece of identifying information, such as a name, date of birth, contact information, sex, race or military personnel information, including occupational specialty, according to the notification.

Military Times 2026-09-24

The stolen data wasn’t encrypted, according to the letter.

CNN 2026-09-25

Two people familiar with the incident told Military Times that approximately four million Defense Department personnel may be affected.

Military Times 2026-09-24
incident27 Sep 04:33Zmulti-sourceOpen finding ↗