Pentagon Personnel Agency Breach Exposed Nearly 3 Million People: DMDC File-Sharing Server Was Accessible to Unauthorized Users for Nine Months
Pentagon Personnel Agency Breach Exposed Nearly 3 Million People: DMDC File-Sharing Server Was Accessible to Unauthorized Users for Nine Months
The U.S. Defense Manpower Data Center (DMDC), the agency that maintains personnel records for the Department of Defense, has begun notifying people that their personal information was exposed in a breach that went undetected for roughly nine months. A notification letter dated September 18 — a copy of which was shared online by a recipient — says the problem was discovered on July 16, 2026: "a security vulnerability in a DMDC file sharing system was discovered, which allowed unauthorized users to access files. DMDC immediately updated the file sharing system to patch the vulnerability and the system was restored." The letter adds that analysis "identified that between October 2025 and the date of discovery, a small number of unauthorized users accessed files on a server containing unencrypted PII."
A Department of War official told CNN that the breach impacts 2.76 million living individuals and 294,000 deceased individuals — just over three million people. The exposed records varied by person but included Social Security numbers alongside names, dates of birth, contact details, demographic data such as sex and race, and military occupational specialties. The letter does not name the affected file-sharing product or describe the vulnerability. DMDC is not a small office: it held at least 60 million records as of fiscal year 2024, covering military and civilian personnel, contractors, family members, retirees and veterans. The agency says it has no indications of misuse of the accessed information so far, and no known cybercrime group has claimed the attack. Affected individuals are being offered 12 months of free credit monitoring through IDX, with enrollment open until August 19, 2027.
The most operationally important fact is the timeline: unauthorized access persisted from October 2025 to mid-July 2026 — nine months — on a server holding unencrypted personally identifiable information, and the exposure ended only because someone found a vulnerability, not because anyone noticed the access itself. DMDC says it has launched privacy and cybersecurity incident response actions in line with U.S. government policies and is assessing the affected system.
What Should You Do?
- If you received a DMDC letter: enroll in the IDX credit monitoring before the August 19, 2027 deadline, and treat your SSN as permanently exposed — credit freezes at the major bureaus remain the strongest personal mitigation.
- If you run file-sharing infrastructure: inventory yours today. The exposure pattern here — an internet-reachable file server with unencrypted PII and no detection on abnormal access — is the default state of many file transfer products, as the long line of MOVEit- and Accellion-style incidents has shown.
- Encrypt at rest: the letter's own language ("unencrypted PII") marks the difference between a patchable incident and a multi-million-record disclosure.
- Log and alert on access behavior: a small number of unauthorized users went unnoticed for nine months; anomaly detection on who reads files — not just who authenticates — is what shortens that window.
The WAF Angle
File-sharing servers are web applications with a dangerous product feature set: anonymous upload endpoints, authentication that is often bolted on, and direct file paths that WAF rules are reluctant to block because legitimate traffic looks nearly identical. Nine months of quiet unauthorized file access is the exact failure mode that edge controls are supposed to compress — if requests to the file-sharing server were inspected, rate-limited and anomaly-scored, unusual access patterns from unfamiliar sources would at least have generated alerts rather than silence. The breach also fits a pattern defense teams should recognize: the vulnerability is discovered during an investigation, patched the same day, and only then does the forensic analysis reveal how long the door had been open. Put file-sharing platforms in the same risk tier as your internet-facing web apps: behind the WAF, in the audit scope, with encryption at rest so that a nine-month access window becomes a nine-month window into ciphertext.