WASHINGTON, D.C. — The Defense Manpower Data Center confirmed a data breach that exposed the personal information of approximately 3 million current and former military personnel and their families. A Pentagon official confirmed that 2.76 million living individuals and 294,000 deceased individuals were affected by the breach.

The Defense Manpower Data Center serves under the Office of the Secretary of Defense to collate personnel, manpower, training, financial, and other data for the United States Department of Defense. The organization has offices in Seaside, California, and Alexandria, Virginia. Based on fiscal year 2024 data, the center holds records for more than 60 million people, including military personnel, civilians, contractors, family members, retirees, and veterans.

A victim notification letter from the Defense Manpower Data Center to affected individuals, reviewed, confirmed the breach timeline and outlined the remediation efforts, though the document itself was not publicly disclosed. The Defense Manpower Data Center is offering year-long credit monitoring and identity-restoration services through IDX to affected personnel. Individuals with questions about the breach can contact IDX at https://response.idx.us/DMDC or 1-855-744-4556.

Active duty personnel and National Guard members can receive free electronic credit monitoring. The Federal Trade Commission states that anyone can place a free credit freeze with Equifax, Experian, and TransUnion.

Justin Sherman, CEO of Global Cyber Strategies, said that having personal data on potentially millions of service members exposed is dangerous as the US wages war on Iran and is in competition with multiple other governments. He added that if a foreign adversary were to obtain this kind of data trove, it could enable phishing, profiling, foreign intel approaches, and much more. US Central Command told lawmakers in the spring that it had received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil US personnel in theater. Justin Sherman said it can be tempting to dismiss the next hack of a database as ‘just another data breach,’ but breaches do not exist in a vacuum.

Why It Matters

The Defense Manpower Data Center holds 60 million records, and the 2026 breach affected approximately 5% of this population, showing the scale of the exposure relative to its total database. The breach coincided with broader cybersecurity concerns, including a separate incident exposing 153 million driver’s licenses in the U.S. and Canada, pointing to systemic risks in data storage across government and private sectors.

In 2015, the FBI's Office of Personnel Management suffered a data breach that exposed 21.5 million records, including sensitive information of federal employees, attributed to Chinese state-sponsored hackers. That breach led to a decade of mandatory credit monitoring for affected individuals. The Office of Personnel Management also reported in 2015 that 4.2 million individuals' data was stolen in a separate breach, demonstrating recurring vulnerabilities in federal personnel data systems. The FBI said it was working around the clock to investigate the cyber incident involving FBIJobs.gov and was in regular communication with anyone who may be impacted—including multiple bureau-wide communications within 24 hours of public reporting.

Timeline

Unauthorized users accessed files on a Defense Manpower Data Center server containing personally identifiable information between October 2025 and July 16, 2026. The Defense Manpower Data Center discovered a security vulnerability in its file-sharing system on July 16, 2026. The agency updated its file-sharing system to address the vulnerability upon discovery.

What's New

Additional reporting provided context on the scale and implications of the breach. He also said that if a foreign adversary were to obtain this kind of data trove, it could enable phishing, profiling, foreign intel approaches, and much more.

The breach coincided with broader cybersecurity concerns, including a separate incident exposing 153 million driver’s licenses in the U.S. and Canada, reflecting systemic risks in data storage across government and private sectors. In 2015, the FBI's Office of Personnel Management suffered a data breach that exposed 21.5 million records, including sensitive information of federal employees, attributed to Chinese state-sponsored hackers, which led to a decade of mandatory credit monitoring for affected individuals. Research titled "Department of Defense Military Manpower Training Report, FY 2000" was published in 1999, and research titled "Department of Defense Military Manpower Training Report FY 1999." was published in 1998.

How Sources Differ

Sources provided different figures regarding the scale of historical breaches and the current incident. The Defense Manpower Data Center website stated that the center holds 60 million records and the 2026 breach affected approximately 5% of this population, totaling 3.05 million individuals. In contrast, the Cybersecurity Resource Center noted that the Office of Personnel Management reported in 2015 that 4.2 million individuals' data was stolen in a separate breach, demonstrating recurring vulnerabilities in federal personnel data systems.

There were also differences in the details provided regarding the timeline and scope. The Defense Manpower Data Center website showed that the breach affected approximately 5% of its 60 million records. The Defense Manpower Data Center breach notification letter specified that unauthorized users accessed files containing personally identifiable information between October 2025 and July 16, 2026.