A breach at a Department of Defense records system has exposed the personal information of 2.8 million living individuals, the Pentagon has confirmed. According to a notification letter posted to Reddit, the stolen data included Social Security numbers, names, addresses, sex, race, and occupational specialty. Officials say the attackers began accessing the system last October.

The compromised system is operated by the Defense Manpower Data Center, which maintains Department of Defense personnel records. That agency reports handling more than 60 million Defense Department person records covering military members, civilians, contractors, retirees, veterans, and their family members. The department has not disclosed how the attackers got into its systems, whether officials have been in contact with anyone responsible, or whether ransom demands were made. Officials said the stolen data has not been misused, but did not explain how they reached that conclusion.

The incident is the second major network breach in recent months to expose sensitive US government personnel records that criminal groups or foreign adversaries could exploit. Last month, the ransomware group ShinyHunters claimed it hacked into FBI systems and stole records of thousands of the agency's current or former employees. Reuters reported that job titles in those records included ones tied to investigating China or Russia.

ShinyHunters said it does not plan to release the information. However, promises from a criminal organization that has hacked and extorted hundreds of organizations carry limited weight, and the group's cyber defenses are unlikely to withstand nation-state intelligence hackers. This week, an FBI official called on group members to surrender.

FBI Cyber Division Assistant Director Brett Leatherman said that the longer members stay involved, the more the bureau learns about them. He said they know how to find the FBI and the FBI knows how to find them, and suggested they reach out first while the choice is still theirs. Leatherman made the statement after Dutch police arrested a ShinyHunters member.

Taken together, the recent breaches amount to one of the largest potential espionage hauls since the 2015 hack of the US Office of Personnel Management. In that breach, China-state hackers obtained 22.1 million records tied to government employees and others who had undergone background checks. The stolen data included nearly the full range of personal information, including fingerprint scans of millions of individuals.

More cybersecurity news from TechManNews.