The Pentagon data breach at the Defense Manpower Data Center covers 3.05 million people: 2.76 million living and 294,000 deceased. Unauthorized users reached unencrypted Social Security numbers and military records between October 2025 and 16 July 2026. Defense Department spokesperson Susan Gough confirmed the figures on 30 September 2026.
Who Is Counted in the 3.05 Million
The affected population is everyone whose file sat on one compromised server, not everyone the agency holds records on. The Defense Manpower Data Center, or DMDC, is the Department of Defense office that keeps personnel and eligibility records for the US military, and it maintains more than 60 million records in total.
The people in its files include active-duty service members, Guard and Reserve personnel, retirees, veterans, Department of Defense civilian employees, contractors and, in some cases, family members. The breakdown confirmed by the department is 2.76 million living individuals and about 294,000 deceased individuals, a total of roughly 3.05 million.
As of 3 October 2026, the department says it has no indication that the accessed information has been misused. It has not explained how it reached that conclusion, a point TechCrunch raised in its 30 September report.
What the Intruders Could Reach
The exposed files held identity data in plain text, which is what makes this breach unusually serious. According to the notification letter, the records contained:
- Social Security numbers: stored unencrypted on the affected server.
- Names and dates of birth: the core identifiers used to open credit in someone’s name.
- Contact information: addresses and other details on file.
- Demographic data: sex and race.
- Military personnel information: including occupational specialties.
DMDC told recipients that the intruders obtained the Social Security number of the letter’s recipient “as well as at least one additional piece of identifying information, such as a name, date of birth, contact information, sex, race or military personnel information”, in the wording of the letter reviewed by Military Times. The department has not said why the data was stored without encryption.
How the Nine Months Unfolded
The intrusion ran for roughly nine months before anyone at the department noticed it.
- October 2025: unauthorized access to files on the affected server begins, according to the department’s own analysis.
- 16 July 2026: DMDC discovers a security vulnerability in a file-sharing system, patches it and starts privacy and cybersecurity incident response.
- 18 September 2026: notification letters to affected individuals are dated.
- 24 September 2026: Military Times reports the breach after reviewing a letter.
- 30 September 2026: Susan Gough, a Department of Defense spokesperson, confirms the affected numbers to TechCrunch while declining to answer questions about the incident.
In its statement, the department said that on discovering the vulnerability, “DMDC immediately initiated privacy and cybersecurity incident response actions in accordance with Office of Management and Budget and Department guidelines and policies”. Nobody has claimed responsibility, and no known criminal group has been linked to the intrusion.
Why You May Have Seen a Figure of 4 Million
Two numbers are in circulation because they come from two different stages of the story. The earliest reporting, on 24 September, put the figure at approximately 4 million Department of Defense personnel potentially affected, based on the notification letter and early briefings.
The confirmed count released at the end of September is lower and more precise: 2.76 million living people and 294,000 deceased, totalling about 3.05 million. That is the figure the department itself has stood behind, and it is the one to use. The earlier estimate has not been formally withdrawn, which is why both still appear in coverage.
The Credit Monitoring Offer and Its August 2027 Deadline
Affected individuals are offered 12 months of free credit monitoring and identity-restoration services through IDX, a breach-response contractor used by the Department of Defense. The offer is not open-ended.
- What is included: one year of credit monitoring plus identity-restoration support.
- How to claim it: using the enrollment code printed in the DMDC notification letter.
- Enrollment deadline: 19 August 2027, as reported by BleepingComputer from the letter.
- What it does not cover: the department has not offered anything beyond the 12 months, even though a Social Security number does not expire.
There is no public lookup tool. The department has not published a way to check whether a particular person is in the affected set, so the letter is currently the only confirmation available.
Steps Security Researchers Recommend Now
The practical advice from security researchers goes further than the free monitoring. Malwarebytes, the security company, published the following steps on 1 October 2026 for people who believe they are affected.
- Enrol in the offered monitoring: use the code in the letter rather than any link sent by email or text.
- Freeze your credit: place a freeze with all three US credit bureaus — Equifax, Experian and TransUnion — which blocks new accounts rather than merely alerting you to them.
- Request an IRS Identity Protection PIN: this stops someone filing a US tax return using your Social Security number.
- Treat unsolicited contact as suspect: be wary of calls, texts or emails that quote military details back at you, and verify any request through a number or address you looked up yourself.
- Harden your accounts: unique passwords and multi-factor authentication on email, banking and benefits accounts.
Our earlier coverage of the limits of credit freezes after an identity-document breach explains why a freeze does not cover every kind of misuse, and the Revolut breach showed how quickly impersonation attempts follow a public disclosure.
Comparisons are being drawn with the 2015 Office of Personnel Management breach, which exposed records on more than 22 million US government employees and applicants. The scale here is smaller, but the data type is similar.
Pentagon Data Breach: Questions Readers Are Asking
How Many People Does the Pentagon Data Breach Affect?
About 3.05 million: 2.76 million living individuals and roughly 294,000 deceased. The Department of Defense confirmed those figures on 30 September 2026.
What Information Was Exposed?
Unencrypted Social Security numbers together with at least one further identifier such as name, date of birth, contact details, sex, race or military personnel information, including occupational specialties.
How Do I Know if I Am Affected?
By the notification letter dated 18 September 2026, which carries an enrollment code. The department has not published a public lookup tool, so there is no official way to self-check.
When Does the Free Credit Monitoring Expire?
The monitoring runs for 12 months, and the deadline to enrol is 19 August 2027 according to the letter as reported by BleepingComputer.
Has Anyone Been Blamed for the Breach?
No. No country, group or individual has been named, and no criminal group has claimed the intrusion. The Pentagon declined to say whether it had received any communication from those responsible.




