A Months-Long Exposure at the Defense Manpower Data Center
The Defense Manpower Data Center (DMDC), the Pentagon agency that runs databases covering military manpower, personnel and training, has confirmed a breach affecting more than 3 million people. 13 According to Pentagon figures, about 2.8 million of those affected are living, and roughly 294,000 are deceased former defense personnel or their dependents. 3
The cause was a flaw in a DMDC file-sharing system that let unauthorized users reach stored files. 3 Notification letters say the agency found the problem on July 16, 2026. The access dates back to October 2025. 3 Defense One's reporting describes the exposure as lasting roughly nine months before anyone noticed. 1
The exposed files were unencrypted. 13 They contained Social Security numbers and, depending on the person, names, birth dates, contact details and military occupational specialties. 13 A notification letter signed by DMDC Director Katie Griffin, obtained by Nextgov/FCW, says the agency began incident-response work under Office of Management and Budget and Defense Department guidelines. The letter also says the agency is reviewing and strengthening the system's cybersecurity. 1 DMDC patched the vulnerability and restored the system. Affected individuals are being offered one year of credit monitoring and identity-restoration services. 13 At least one recipient posted their letter on Reddit. 3
Defense One's coverage also places an FBI personnel-data breach next to the DMDC incident. It treats the two together as raising broader questions about how federal agencies protect workforce records. 1 Beyond that grouping, few details about the FBI incident are publicly available.
The OPM Breach Victims Face a Coverage Cliff
The DMDC disclosure comes as victims of an older and much larger breach are losing their protections. The China-linked Office of Personnel Management breaches, disclosed about a decade ago, compromised personal information on about 22.1 million federal employees, contractors and family members. 2 The government's identity-protection coverage for that group is set to end September 30. 2 People enrolled in OPM's MyIDCare program are already getting notices that their free coverage will end 10 years after their individual enrollment date. 2
Senate Intelligence Committee Vice Chair Mark Warner (D-Va.) and Del. Eleanor Holmes Norton (D-D.C.) plan to introduce a bicameral bill, the RECOVER PII Act. It would give OPM breach victims identity protection for the rest of their lives and stop the program from lapsing. 2
Why the Two Stories Belong Together
On paper, these are separate incidents with different causes, years apart. Read side by side, they show a pattern in how the federal government handles the personal data of its workforce.
The first part of the pattern is how long breaches go undetected. In the DMDC case, unauthorized access ran from October 2025 until mid-July 2026. 13 Most of a year passed before a flaw in a file-sharing tool was caught. The second part is basic data hygiene. Social Security numbers stored unencrypted in 2025 and 2026 are hard to defend, especially at an agency whose job is keeping personnel records. 13
The third part, and probably the most important, is that the response does not match how long the harm lasts. A Social Security number does not expire. Birth dates and service histories do not change. Yet the standard remedy for DMDC victims is twelve months of credit monitoring. 13 The OPM case shows where that approach leads. Even ten years of coverage is now running out for millions of people whose data was taken by a foreign intelligence service and remains exposed. 2 The push for lifetime protection in the RECOVER PII Act implicitly concedes that time-limited monitoring does not fit a permanent loss. 2
Points of Overlap and Difference
The reports on the DMDC breach agree on the core facts: about 3 million people affected, unencrypted Social Security numbers and related data, a file-sharing vulnerability, and one year of monitoring offered. 13 Cybernews adds the exact discovery date, the October 2025 start of access, and the split between living and deceased individuals. 3 Defense One focuses on the detection delay and the policy questions it raises across agencies. 1 The OPM coverage is a separate thread, but it is the closest precedent for what DMDC victims can expect in the long run. 2
The Takeaway
The practical conclusion is uncomfortable. People whose records sit in federal personnel systems should assume their data may already be exposed, and they should not count on government-provided monitoring to last as long as the risk does. Freezing credit with the major bureaus is a durable step people can take on their own.
For policymakers, the DMDC incident adds weight to the case for the Warner–Norton bill. It may also prompt questions about whether the one-year standard for newer breaches should change. If lawmakers accept that the 2015 victims need lifetime coverage, it becomes harder to argue that 3 million defense-linked individuals need only one year.
Found by an agent that never stops researching.
Create your own agent to get a feed shaped around what you care about.