Pentagon data breach of military personnel raises national security concerns
By Sean Lyngaas, Davis Winkie, CNN
(CNN) — A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national security experts.
“Unauthorized users” gained access to a vulnerable computer server belonging to the Defense Manpower Data Center (DMDC) beginning last October, but it wasn’t until nine months later, in July, that the Pentagon discovered and remediated the issue, according to a letter the center sent to victims of the breach reviewed by CNN.
The DMDC maintained at least 60 million records as of fiscal 2024, according to its website. It’s unclear how many have been impacted, but Military Times reported that four million Department of Defense personnel could be affected by the breach.
The Pentagon currently “does not have any indications of misuse” of the breached data, according to the letter. But the breached data is a potential goldmine for foreign intelligence services looking to track US military personnel, or cybercriminals looking to extort them (were they to acquire the data), according to experts.
One piece of data accessed by the intruders in some cases was the “occupational specialty” of military service members, according to the letter, which is dated this month. That, when combined with other datasets using identifiers like Social Security numbers, could give foreign adversaries a clearer read on who does what for the US military in various parts of the world.
It’s unclear who was behind the breach. A Pentagon spokesperson did not immediately respond to CNN’s questions, including who the culprit was.
US military leaders have repeatedly warned their troops that their phones and online accounts could be targets during the war with Iran. US Central Command, which spans the Middle East and beyond, told lawmakers in the spring that it had “received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil US personnel in theater.”
A bad actor could pair the information taken from DMDC with other commercial datasets to “learn about or even target [defense personnel] based on their earnings, debts, marriages, spending habits, browsing activities, and worse,” said Justin Sherman, CEO of advisory firm Global Cyber Strategies and the author of an upcoming book on the data broker industry.
The DMDC is “the one, central access point” for information on Department of Defense entitlements, benefits and “medical readiness” for military personnel, veterans and their families, according to the center’s website.
“The services and access to data we provide support so many vital government entities,” the DMDC website says, “including the legislative branch, human services, national defense, labor, healthcare, finance, veterans affairs, research, and more.”
The stolen data wasn’t encrypted, according to the letter. Encrypting sensitive data is a standard security practice.
“We are taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system,” the letter says while offering victims a year of credit monitoring services.
“On its own, having personal data on potentially millions of service members exposed is dangerous as the US wages war on Iran and is in competition with multiple other governments,” Sherman told CNN. “If a foreign adversary was to get this kind of data trove, it could enable phishing, profiling, foreign intel approaches, and much more.”
The-CNN-Wire
™ & © 2026 Cable News Network, Inc., a Warner Bros. Discovery Company. All rights reserved.