Pentagon Personnel Agency Data Breach Impacts 3 Million People
The US Defense Manpower Data Center (DMDC), which maintains personnel records for the Pentagon, has started notifying people that their personal information was exposed.
According to the DMDC’s notice, unauthorized users had access to one of its file-sharing servers for roughly nine months.
A copy of the notification letter, dated September 18 and shared online by a recipient, says the problem was discovered in mid-July.
“On July 16, 2026, a security vulnerability in a DMDC file sharing system was discovered, which allowed unauthorized users to access files. DMDC immediately updated the file sharing system to patch the vulnerability and the system was restored,” the letter reads.
The letter does not name the affected file-sharing product or describe the vulnerability.
“Analysis identified that between October 2025 and the date of discovery, a small number of unauthorized users accessed files on a server containing unencrypted PII,” the letter says.
Advertisement. Scroll...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE