By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Pentagon Data Breach Exposes 2.8 Million Military Personnel Records

The U.S. Department of Defense is in the process of notifying more than 2 million current and former military personnel that their sensitive personal information has been compromised through a breach of one of its networks. This incident marks the second significant data exposure involving sensitive government information in recent months. The compromised records contain highly sensitive data, including Social Security numbers, full names, residential addresses, gender, race, and occupational specialties. The inclusion of occupational specialty data is of particular concern, as it could provide foreign adversaries with valuable intelligence for identifying high-value military personnel for recruitment or targeting by intelligence agencies. Hackers first gained unauthorized access to a system managed by the Defense Manpower Data Center (DMDC) starting in October. The DMDC is responsible for collating personnel records for the Department of Defense. The Pentagon has stated that the breach ultimately affected the records of approximately 2.8 million living individuals. This breach follows another significant incident last month where the ransomware group ShinyHunters claimed to have infiltrated FBI systems, stealing records of thousands of current and former agency employees. Reports from Reuters indicated that the compromised FBI records included job titles related to investigations into China and Russia, highlighting the potential for such data to be exploited by foreign entities. The ongoing nature of these breaches underscores vulnerabilities in federal data security and the potential for widespread impact on individuals whose personal and professional information is exposed. The DMDC's role in managing vast amounts of sensitive military personnel data makes its network a critical target for malicious actors seeking to gain strategic advantages or cause disruption. The full extent of the damage and the specific methods used by the attackers are still under investigation, but the immediate concern is the protection of the affected individuals from identity theft and other forms of exploitation. The U.S. government faces increasing pressure to bolster its cybersecurity infrastructure to prevent future breaches of this magnitude and to safeguard the personal information of its service members and employees.
Original source — read the full reporting at the publisher:
Read on Ars TechnicaGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.