Skip to content

Cart

Your cart is empty

Article: DoD Breach May Affect 4 Million

Illustrative photo: An Airman receives a new Common Access Card at Hanscom Air Force Base, Massachusetts, on March 1, 2024. A Defense Manpower Data Center breach exposed unencrypted personal information belonging to Defense Department personnel. U.S. Air

DoD Breach May Affect 4 Million

PHOTO CAPTION: Illustrative photo: An Airman receives a new Common Access Card at Hanscom Air Force Base, Massachusetts, on March 1, 2024. A Defense Manpower Data Center breach exposed unencrypted personal information belonging to Defense Department personnel. U.S. Air Force photo by Mark Herlihy.

A Defense Department data breach exposed unencrypted personal information, including Social Security numbers and military personnel data, and approximately 4 million DoD personnel may have been affected, according to new reporting from Military Times.

The breach involved a file sharing system operated by the Defense Manpower Data Center, the agency that maintains personnel information for millions of current and former members of the Defense Department community.

DMDC discovered a security vulnerability in the system on July 16.

An analysis conducted afterward determined that unauthorized users had accessed files containing unencrypted personally identifiable information during a period stretching from October 2025 through July 16, according to a breach notification letter reviewed by Military Times.

The letter was sent Sept. 18 to an individual whose information was contained in the affected files.

For that individual, the compromised information included a Social Security number and at least one additional identifying data point.

Other information contained in affected files could include names, dates of birth, contact information, sex, race and military personnel information such as occupational specialty.

The exact number of people affected has not been publicly confirmed by the Defense Department.

However, two people familiar with the incident told Military Times that approximately 4 million Defense Department personnel may have been affected.

The Defense Department and DMDC had not responded by publication time to Military Times questions seeking confirmation of that number or information about who gained access to the files.

The notification says there is currently no indication that the recipient's personal information has been misused.

Affected individuals are being offered one year of credit monitoring and identity restoration services through IDX, a private company contracted by the Defense Department.

The scale of the systems maintained by DMDC makes the incident particularly significant.

DMDC describes itself as the Defense Department's central source for identifying, authenticating, authorizing and providing information about personnel during and after their affiliation with the department.

The agency says it maintains more than 60 million Defense Department records involving military personnel, civilian employees, contractors, family members, retirees and veterans.

That does not mean 60 million people were affected by this breach.

The potential number involved in this incident remains approximately 4 million based on sources familiar with the investigation, and DoD has not publicly confirmed that estimate.

According to the notification, the vulnerability involved a file sharing system that allowed unauthorized users to access files on a server.

DMDC said it updated the affected system to patch the vulnerability after discovering the problem and then restored the system.

The notification does not publicly identify the unauthorized users or explain why the files were accessed.

Military Times also reported that Lt. Gen. Paul Stanton, director of the Defense Information Systems Agency, is leading the response, according to a person familiar with the matter.

That source said a broader cyber review is underway to look for additional vulnerabilities or unauthorized access across Defense Department systems.

DoD had not publicly confirmed details of that broader effort by the time the report was published.

For people receiving breach notifications, the immediate concern is the type of information involved.

Social Security numbers can remain useful to identity thieves long after a breach occurs, while other personal information can be combined with them for fraudulent applications, account takeovers and other forms of identity theft.

The Defense Department says it currently has no indication that the information identified in the notification has been misused.

But the notification confirms that unauthorized users accessed files containing unencrypted personal data, and affected individuals are now being offered monitoring and identity restoration services.

The full scope of the breach, who accessed the information and how many Defense Department personnel were affected remain unanswered questions.

(Source: OAF Nation)

MORE FROM THE

OAF NATION NEWSROOM

Illustrative file photo: Military family housing at Stearley Heights on Kadena Air Base, Okinawa, undergoes renovation in December 2023. About 25 percent of Okinawa's 7,273 on base family homes are currently under renovation as incoming families face

Okinawa Housing Shortage Strains Military Families

Military Families Spend Weeks in Hotels as Okinawa Housing Shortage Worsens

Read more
Illustrative photo: The Appellate Division Courthouse in Manhattan houses the First Department, which on Sept. 24 unanimously reversed Robert Fulladosa's five year gun conviction after ruling that the search that uncovered the weapon was unlawful. Photo

Court Overturns Gun Conviction

Appeals Court Throws Out Five Year Gun Conviction After Ruling Police Search Was Illegal

Read more