The Pentagon has disclosed that an information system operated by the Defense Manpower Data Center was accessed without authorization by a small number of users between October 2025 and July 2026. A U.S. defense official said the DMDC remediated the vulnerability as soon as it was discovered. The official also said there is no evidence so far that the compromised data has been misused. The affected information is personally identifiable data belonging to nearly three million military and civilian personnel.

DMDC functions as the Pentagon's central personnel database. It holds information on active-duty and reserve members of the military, civilian employees, contractors, retirees, veterans, and military family members. The repository contains more than 60 million records in total. Because it also lists the roles and job details of the people in it, a breach of the system could expose the identities of personnel assigned to sensitive positions tied to national security.

The Pentagon did not say who was behind the intrusion, and it did not explain how it detected the vulnerability. The absence of evidence that the data has been exploited does not rule out the possibility that the intruders are holding the information for later use. For the nearly three million people whose records were exposed, the incident carries privacy and personal security risks that persist regardless of the fix.

The breach lands against a backdrop of sustained digital probing of government systems. Hackers reportedly breached the U.S. Treasury Department in early 2025, an operation that extended to the Treasury Secretary's PC. The CanisterWorm malware recently spread and wiped Iranian machines, and Iran claimed that Western-made routers from Cisco and others failed just as U.S. and Israeli bombing campaigns against it began during the first quarter of this year. U.S. authorities also released a warning that Iranian hackers are targeting Siemens controllers in an effort to sabotage critical infrastructure.

Remediating the vulnerability does not undo the exposure of data such as Social Security numbers and employment histories. The people affected will need to stay alert to criminals, intelligence services, and other threat actors well after the incident leaves the news cycle. For an individual in a national security-related position, the article noted, a year of free credit monitoring would not be sufficient protection.

The incident ranks among the larger exposures of federal personnel data in recent years, given the size of the DMDC repository and the range of people it covers. The official statement did not address whether affected individuals have been notified. It also did not indicate whether any additional safeguards have been put in place beyond the remediation of the specific vulnerability.

More cybersecurity news from TechManNews.