The U.S. authorities is reportedly alerting hundreds of thousands of present and former U.S. navy service members and workers that their private info was stolen throughout a months-long breach of the Pentagon’s personnel information, the newest in a spate of thefts involving federal staff’ knowledge in latest months.
An information breach notification from the Protection Manpower Knowledge Middle (DMDC) shared on Reddit says that a number of unauthorized customers exploited a safety vulnerability in an unspecified file-sharing system over a number of months between October 2025 and mid-July 2026.
The breach uncovered personally identifiable info, together with Social Safety numbers, alongside an individual’s identify, date of delivery, intercourse, race, and different details about their navy service. The discover says that the personnel information have been unencrypted.
In response to CNN and Federal News Network, a Pentagon official stated the breach impacts about 2.8 million dwelling individuals, and near 300,000 people who find themselves deceased.
The U.S. navy has 1.3 million lively service members as of March.
The DMDC might not be broadly identified to most people, however serves as one of many Division of Protection’s records-keeping models. The DMDC maintains over 60 million information for U.S. navy and civilian workers and their members of the family to assist decide advantages and entitlements, resembling healthcare and retirement. The unit additionally gives a crucial service because the navy’s “main identification administration supplier,” which hyperlinks lively service members, workers, and contractors to credentials, resembling good playing cards and passwords. These are used to entry Pentagon pc techniques, buildings, and bases.
“We make it possible for the suitable individuals get entry and the improper individuals don’t: safety of identification info is paramount,” the DMDC’s web site reads.
The Division of Protection, which oversees the DMDC, stated it doesn’t have any indication that the data was misused, however didn’t say the way it reached that conclusion. TechCrunch contacted a Pentagon spokesperson to ask if officers had any communications from the hackers, whose identities should not identified, however we didn’t hear again.
That is the newest main breach of federal staff’ private info in latest months, following a latest breach on the FBI earlier in September attributed to the ShinyHunters hacking group. The hackers advised TechCrunch that that they had taken the non-public info of many of the FBI’s brokers and staffers, together with candidates. The breach has been billed as a “counterintelligence catastrophe” amid the dangers {that a} international authorities might get hold of and use the data to profile, goal, or coerce federal staff into handing over delicate info.
The ShinyHunters hackers have stated that they won’t publicly launch the stolen FBI knowledge.
Each breaches involving the FBI and the DMDC mirror related thefts of presidency personnel information up to now. In 2015, a breach of the U.S. authorities’s human assets division, generally known as the Workplace of Personnel Administration, was broadly attributed to China. The theft allowed the hackers to steal the personal information of greater than 22 million U.S. authorities workers, a lot of whom had safety clearances.
Did you obtain a discover about this knowledge breach? We wish to hear from you. You’ll be able to contact this reporter securely on Sign at zackwhittaker.1337, or attain him by electronic mail at zack.whittaker@techcrunch.com.
Whenever you buy by means of hyperlinks in our articles, we could earn a small fee. This doesn’t have an effect on our editorial independence.
