The Defense Manpower Data Center (DMDC), which keeps personnel records for the U.S. Department of Defense, is notifying people that unauthorized users had access to files holding their unencrypted Social Security numbers, birth dates and other personal details for about nine months. A Pentagon official put the number affected at nearly 2.8 million living people and about 294,000 people who have died, more than 3 million in all. A Social Security number cannot easily be changed, so the risk for those affected outlasts the 12 months of free monitoring now on offer.

What happened

Notification letters from DMDC began going out on September 18, according to Military Times, which reported the breach on September 24. The account below is drawn from that letter as quoted in reporting, from a Pentagon statement and from the official notice site.

  • How access happened. DMDC says it discovered "a security vulnerability in a DMDC file sharing system" on July 16, 2026, and that "a small number of unauthorized users" had used it to access files, as quoted by BleepingComputer. The letter, as quoted by Military Times, says the users "accessed files on a server containing unencrypted personally identifiable information".
  • How long. Access ran from October 2025 until July 16, 2026, when the flaw was found. The department says it patched the vulnerability on discovery and that DMDC "immediately initiated privacy and cybersecurity incident response actions".
  • What was exposed. Social Security numbers, names, dates of birth, contact information, sex, race and military personnel information such as military occupational specialty. Reporting says what was exposed varies from person to person.
  • How many. On September 28 a Pentagon official told Federal News Network that nearly 2.8 million living people and 294,000 deceased people were affected. Military Times, citing two people familiar with the incident, had earlier reported that about 4 million might be affected; the department did not give it a figure at the time.
  • Misuse. The official told Federal News Network: "There's no indication that anyone's personal information has been misused."

The department is offering 12 months of credit monitoring and identity restoration through IDX, a breach response company it has contracted. The official notice site describes the monitoring as free and enrolment requires the code in the letter. BleepingComputer reports that the enrolment deadline is August 19, 2027.

The background

DMDC is not a niche office. According to Federal News Network, Military Times and BleepingComputer, it holds records on more than 60 million people: service members, veterans, retirees, Defense Department civilian employees, contractors and military family members. BleepingComputer dates the center's founding to 1974. Because the center serves as the department's personnel data hub, people who left the military or a defense job long ago can still be in its files, and so can their dependents.

The data types matter. A name, date of birth and Social Security number together are what a criminal needs to try to open credit, file a tax return or claim benefits in someone else's name. The Federal Trade Commission describes two free protections that make it harder for someone to open credit in your name, a credit freeze and a fraud alert, and the IRS runs an identity protection program aimed specifically at fraudulent tax returns. Both are covered below.

We could not find a Defense Department press release about the breach. The government's account so far consists of the letters, the IDX notice site and statements given to reporters.

Why it matters

Three details stand out in the department's own account. First, the data was unencrypted, so anyone who could reach the files could read them. Second, the access lasted about nine months before it was found, by DMDC's own dating. Third, the affected group includes people who have died, whose identities can be used in benefit and tax fraud and whose families may not be watching for it.

The department's statement that there is "no indication" of misuse should be read for what it is: a statement about what has been seen so far, not an assurance that the data is safe. Exposed Social Security numbers stay useful to criminals for years, and the free monitoring lasts one year.

There is also a risk of scams that imitate the notice. The genuine notice is a DMDC letter with an enrolment code for the IDX site, so an unexpected email or text claiming to be about this breach deserves caution.

What we do not know yet

  • Who the unauthorized users were. The department has not said, and the official declined to give details.
  • Whether data was copied. The notices describe access to files. Reporting has not established whether, or how much, data was taken.
  • Why the records were unencrypted. The Pentagon declined to explain this to Federal News Network.
  • Which system and which flaw. DMDC has named only "a file sharing system". The product and the vulnerability have not been disclosed.
  • The final count. The official figure is just over 3 million; one earlier report cited about 4 million. Whether the count will change is not known.
  • How to check. There is no public lookup tool. The only confirmation is a letter.

What it means for you

If you served, work or worked for the Defense Department or a contractor, or are a military family member, the steps below are drawn from the IDX notice site, the FTC and the IRS.

  1. Watch for a DMDC letter. Enrol only with the code it contains, and go to the IDX site yourself rather than following a link in an email or text.
  2. Take the free monitoring. The notice site lists 12 months of credit monitoring and identity restoration at no cost.
  3. Consider a credit freeze. According to the FTC, a freeze is free, does not affect your credit score, stays in place until you remove it, and means "nobody can open a new credit account in your name, including you." You must contact Equifax, Experian and TransUnion separately. The IDX site notes that a freeze may need to be lifted temporarily to activate its monitoring.
  4. Or place a fraud alert. An initial fraud alert is free, lasts one year and is renewable; you contact one bureau and it notifies the other two. Service members can place an active duty alert, which lasts one year and can be renewed for the length of a deployment.
  5. Get an IRS Identity Protection PIN. The IRS IP PIN is a six-digit number that "prevents someone else from filing a tax return using your Social Security number". Anyone with an SSN or ITIN who can verify their identity can get one, fastest through an IRS online account. A new PIN is issued each year, and the IRS will never ask for it by phone, email or text.
  6. Check your credit reports. Free reports are available at annualcreditreport.com. Look for accounts and credit inquiries you do not recognize.
  7. Report fraud if you find it. The FTC's IdentityTheft.gov takes reports and builds a recovery plan. The IDX notice site also advises filing a police report.
  8. Families of the deceased. Records of about 294,000 people who have died were included. The reporting so far does not say how DMDC is contacting their families, so relatives handling an estate may want to watch for a letter.