Skip to content
Bramble

US

Pentagon personnel database breach exposes data on nearly 3 million people

A Defense Manpower Data Center system was accessed without authorisation between October 2025 and July 2026, exposing Social Security numbers and other records of about 2.8 million living people and nearly 300,000 deceased people, a Pentagon official said.

4 outlets · 1L · 1C · 2R First reported Account updated
Image: ABC News
Image: TechCrunch
Image: Just the News

1 / 3

The story, neutrally told

A Pentagon personnel system run by the Defense Manpower Data Center (DMDC) was accessed without authorisation, exposing sensitive records of military and civilian personnel. A defense official told ABC News the breach affected 2.76 million living people and another 294,000 who are deceased; TechCrunch, citing CNN and Federal News Network, put the figures at about 2.8 million and close to 300,000. The unauthorised access ran from October 2025 to July 2026, when DMDC said it discovered and fixed the vulnerability.

The exposed data included Social Security numbers and details of jobs held; a notification shared on Reddit, described by TechCrunch, also lists names, dates of birth, sex and race, and says the records were unencrypted. Defense officials said they have found no evidence the data has been misused; ABC reports they are offering identity protection and credit monitoring, while TechCrunch notes the department did not say how it reached that conclusion. DMDC holds more than 60 million records on troops, civilians, contractors, retirees and family members, and manages identity credentials for access to Pentagon systems and bases.

Both outlets place the breach alongside a recent FBI breach attributed to the ShinyHunters group, which has said it will not release the stolen data; the identities of the Pentagon hackers are not known. TechCrunch compares the incident with the 2015 Office of Personnel Management breach, broadly attributed to China, which affected more than 22 million government employees.

Every sentence links to the reporting it rests on.

Left1 outlet

Framing
Leads with national-security implications and the scale of exposure, sourced to a defense official, then links to the FBI jobs-portal breach.
Emphasis
Exact figures, job details in files, official statement, FBI employee guidance.
Leaves out or plays down
Does not mention the records were unencrypted or the 2015 OPM comparison.
Charged language
“sprawling personnel database”“massive swath”
For example
“The scope and sensitivity of the exposed information could raise national security concerns” — ABC News

Centre1 outlet

Framing
Frames it as theft by hackers in a months-long breach, part of a spate of federal-worker data thefts, with security-editor context.
Emphasis
Unencrypted records, unverified no-misuse claim, DMDC's role, historical OPM comparison.
Leaves out or plays down
Gives rounded figures and does not report the FBI employee guidance on media contact.
Charged language
“counterintelligence disaster”“Hackers stole”
For example
“the latest in a spate of thefts involving federal workers’ data in recent months” — TechCrunch

Right2 outlets

No right outlet in our sources has covered this story yet.