Popular Articles
Today Week Month Year


Pentagon Breach Reportedly Exposes Data of 3 Million People
By Garrison Vance // Sep 30, 2026

A personnel system breach targeting the Department of War reportedly exposed sensitive data on more than three million people, including military personnel and their families, according to several media outlets citing unnamed U.S. defense officials.

The Defense Manpower Data Center (DMDC) system was accessed by a small number of unauthorized users between October 2025 and July 2026, affecting approximately 2.76 million living individuals and another 294,000 who are deceased, officials told CNN and ABC News [1].

The disclosure follows a separate breach claim involving the Federal Bureau of Investigation's (FBI) jobs website. According to the reports, the exposed files include Social Security numbers, personal details, and information about military jobs and occupational specialties [1]. The War Department has not officially confirmed the breach, and no public statement has been issued regarding who was behind the intrusion or what was done with the information accessed.

The reported scope of the breach places it among the larger known compromises of U.S. government personnel data in recent years. DMDC maintains more than 60 million records overall, including information on active-duty and reserve troops, civilian employees, contractors, retirees, veterans and military family members [1].

Scope of Data and Affected Records

Military Times initially reported the leak last week, citing an internal breach notice received by an affected individual. The publication said two unnamed defense officials confirmed the authenticity of the letter [1]. According to the notice, DMDC stated that a security vulnerability in a file-sharing system allowed unauthorized users to gain access to unencrypted personal information [1].

The types of data reportedly exposed could be used for identity theft, targeted phishing, or intelligence-gathering purposes. The U.S. intelligence community has previously documented efforts by foreign adversaries to cross-index hacked data to identify and expose intelligence officers and other sensitive personnel [2]. The breach of the Office of Personnel Management (OPM) in 2015, which exposed tens of millions of records, remains a benchmark for the potential national security consequences of such intrusions [3].

Timeline, Patch and Official Response

Unauthorized access to the DMDC system began in October 2025 and continued until July 2026, according to defense officials cited in media reports [1]. DMDC said the system was patched immediately after the vulnerability was discovered, nearly nine months after unauthorized access began, according to the breach notice [1]. Affected individuals were offered one year of free credit monitoring services [1].

The duration of unauthorized access – approximately nine months – raises questions about the effectiveness of the War Department's cybersecurity monitoring and incident detection capabilities. A 2024 breach of a major IT provider servicing the U.S. military-industrial complex similarly raised concerns about the safety of sensitive files [4].

The incident also underscores long-standing challenges in defending government networks. A 2015 report noted that the U.S. military has not done a good job defending its cyber borders, even as hack attacks have become more frequent and costly [3].

More recently, Microsoft's security plan submitted to the War Department in February 2025 failed to disclose that it was relying on employees based in China to work on highly sensitive systems, despite requirements mandating that such work be performed by U.S. citizens or permanent residents [5]. The War Department's approach to cybersecurity has drawn scrutiny from watchdogs who note that surveillance and security systems can themselves become vulnerabilities [6].

Separate FBI Recruitment Website Breach Claim

Meanwhile, the FBI is investigating a separate breach claim involving its recruitment website. Last week, the hacking group ShinyHunters claimed it had stolen personal data on nearly all FBI agents, their spouses, and job applicants [1]. The group said the attack was not financially motivated and, instead of a ransom, demanded that the FBI remove a cybersecurity advisory published in May that ShinyHunters says contains false allegations about them [1].

The FBI has said it is investigating and has notified employees, but has not yet established where the breach occurred or confirmed the scale of the theft [1]. The claim remains unverified by the bureau.

The incident follows a pattern of high-profile data breaches affecting government agencies and their contractors. A breach at ID verification firm IDScan, confirmed in September 2026, involved the theft of more than 150 million driver's licenses from its cloud systems [7].

The FBI breach claim, if confirmed, would represent a significant compromise of personal information belonging to law enforcement personnel and their families. The bureau's public response has been limited to acknowledging the investigation and notifying affected individuals. No timeline has been provided for when the FBI expects to complete its assessment of the breach's scope and origin.

The incidents highlight the persistent vulnerability of government data systems to unauthorized access. The 2015 OPM breach exposed tens of millions of records, and subsequent reporting indicated that Russia and China were cross-indexing hacked U.S. databases to identify intelligence officers [2].

More than a decade later, the War Department continues to grapple with securing its networks against determined adversaries. The DMDC breach, if confirmed, would add to a growing list of data compromises affecting U.S. military personnel and their families.

References

  1. RT. "Pentagon breach exposed data on over 3 million people – media." RT. September 29, 2026.
  2. NaturalNews.com. "Russia China cross-indexing hacked data to expose blackmail US spies." NaturalNews.com. September 3, 2015.
  3. NaturalNews.com. "US ramps up spending on cyber defenses as virtual war spreads globally." NaturalNews.com. October 14, 2015.
  4. NaturalNews.com. "National security BREACHED after hackers break into most sensitive US government files." NaturalNews.com. July 30, 2024.
  5. NaturalNews.com. "Microsofts security plan omissions raise concerns over foreign influence and cybersecurity." NaturalNews.com. August 26, 2025.
  6. ZeroHedge. "The Pentagon Flocked Itself. Should Big Brother Be Worried?" ZeroHedge. September 25, 2026.
  7. TechCrunch. "ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen." TechCrunch. September 10, 2026.

Explainer Infographic



Take Action:
Support NewsTarget by linking to this article from your website.
Permalink to this article:
Copy
Embed article link:
Copy
Reprinting this article:
Non-commercial use is permitted with credit to NewsTarget.com (including a clickable link).
Please contact us for more information.
Free Email Alerts
Get independent news alerts on natural cures, food lab tests, cannabis medicine, science, robotics, drones, privacy and more.

NewsTarget.com © All Rights Reserved. All content posted on this site is commentary or opinion and is protected under Free Speech. NewsTarget.com is not responsible for content written by contributing authors. The information on this site is provided for educational and entertainment purposes only. It is not intended as a substitute for professional advice of any kind. NewsTarget.com assumes no responsibility for the use or misuse of this material. Your use of this website indicates your agreement to these terms and those published on this site. All trademarks, registered trademarks and servicemarks mentioned on this site are the property of their respective owners.

This site uses cookies
News Target uses cookies to improve your experience on our site. By using this site, you agree to our privacy policy.
Learn More
Close
Get 100% real, uncensored news delivered straight to your inbox
You can unsubscribe at any time. Your email privacy is completely protected.