Interestana
Home/News/Hackers Stole Pentagon Personnel Records of 3 Million
BleepingComputer••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Hackers Stole Pentagon Personnel Records of 3 Million

The Pentagon's Defense Manpower Data Center (DMDC) is notifying over 3 million military service members that their personal data was stolen by hackers who breached the Defense Department's human resources management system in October 2025. This breach compromised sensitive information, including names, social security numbers, and other personally identifiable details of current and former military personnel, as well as their dependents. The DMDC, which is responsible for managing personnel data for the U.S. military, discovered the intrusion during a routine security audit. The exact number of individuals affected is estimated to be approximately 3,000,000, though the DMDC has stated that the full scope of the compromise is still under investigation. The breach occurred within the DMDC's systems, which store vast amounts of data related to military service members, including their employment history, pay, benefits, and personal contact information. The hackers gained unauthorized access to this system, allowing them to exfiltrate a significant volume of sensitive records. In response to the breach, the DMDC is offering identity theft protection services to all affected individuals. These services are intended to help mitigate the risks associated with the exposure of personal data, such as fraudulent activity and identity theft. The notification process began in early November 2025, with affected individuals receiving letters detailing the nature of the breach and the steps they can take to protect themselves. The Pentagon has not publicly identified the specific hacking group responsible for the attack, nor has it disclosed the methods used to gain access to the system. However, cybersecurity experts suggest that such sophisticated breaches often involve advanced persistent threats (APTs) or the exploitation of previously unknown zero-day vulnerabilities. The incident highlights ongoing cybersecurity challenges faced by government agencies in protecting sensitive data from sophisticated adversaries. The DMDC has stated that it is working closely with federal law enforcement and cybersecurity agencies to investigate the breach thoroughly and to enhance its security protocols to prevent future incidents. This event underscores the critical importance of robust cybersecurity measures within military and government organizations, particularly those handling large databases of personal information. The long-term implications of this data theft are still unfolding, as affected individuals will need to remain vigilant against potential misuse of their stolen information. The DMDC has established a dedicated call center and website to provide support and information to those impacted by the breach, urging them to monitor their financial accounts and credit reports closely.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next