The US Department of Defense’s Defense Manpower Data Center (DMDC) has begun notifying more than 3 million people that their personal data was stolen from its human resources management systems, according to breach notification letters reported on 1 October 2026.
What happened
- Attackers exploited a vulnerability in file-sharing infrastructure and had access between October 2025 and July 2026.
- Those affected include about 2.8 million living people and 294,000 who have died.
- Stolen data includes Social Security numbers, names, dates of birth, contact details, and military personnel information.
- The DMDC says “a small number of unauthorized users” accessed the data; no attacker has been publicly named. It is offering 12 months of credit monitoring.
Why it mattered
It is one of the largest breaches of US government personnel data since the 2015 OPM breach, and the attackers went unnoticed for around nine months.
Lessons for organisations
Treat file-sharing and transfer systems as high-risk, internet-facing assets: patch them quickly, log and review access to bulk HR data, and alert on unusual downloads so a breach is found in days, not months.
Source: BleepingComputer
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.