The U.S. Department of Defense is notifying roughly 3.05 million people that their personal information was exposed in a breach of the Defense Manpower Data Center (DMDC), the agency that has served as the Pentagon's central personnel records hub since 1974. The count includes 2.76 million living individuals and about 294,000 people who have since died.

According to the notification, unauthorized users exploited a security vulnerability in a DMDC file-sharing system that gave them access to files on a server holding unencrypted personally identifiable information. The access window ran from October 2025 until July 16, 2026, when the flaw was discovered. That means whoever got in had roughly nine months of undetected access before the system was patched and restored.

The exposed data varies by person but includes Social Security numbers paired with names, dates of birth, contact information, sex, race, military service details and occupational specialties. Affected people include current and former defense personnel and their dependents. DMDC held at least 60 million records in fiscal year 2024, so the breach touched only a portion of its holdings, but the categories exposed are the ones most useful for identity fraud and for targeting people with security clearances.

The Pentagon says it has "no indications of misuse" of the data. It has not said who was behind the intrusion, whether files were copied out, or how it reached its no-misuse conclusion. No criminal group had publicly claimed responsibility at the time of the notices. The department is offering 12 months of free credit monitoring through breach response firm IDX, with enrollment open until August 19, 2027, and says it is "taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system."

Two details will draw the most scrutiny. First, the data was stored unencrypted, a basic control that would have limited the damage even after the file-sharing flaw was exploited. Second, the detection gap. Nine months of access to a system holding Social Security numbers for military families points to weak monitoring of who was pulling files and how much.

For anyone who receives a letter, the practical steps are the standard ones: enroll in the free monitoring, place a credit freeze with Equifax, Experian and TransUnion, and treat unexpected calls, texts or emails that reference military service details with suspicion. Data like occupational specialty and service history makes phishing and pretexting far more convincing, and that risk outlasts any 12-month monitoring offer.