The Pentagon holds the life stories of a country. Names and Social Security numbers. Along with information about what jobs people have held inside the military apparatus. That is exactly where a door stood open for months. Unauthorized users accessed a Defense Manpower Data Center system between October 2025 and July 2026. According to a U.S. defense official, 2.76 million living people and another 294,000 deceased people were affected. Altogether, that is more than 3.05 million people. The agency did not discover the vulnerability until July and then closed it.
The DMDC is one of the Pentagon's major personnel archives and manages more than 60 million records. They include active-duty troops and reservists. Civilian employees and contractors as well. Retirees and veterans are in there too. Military family members as well. The breach therefore hit a collection where military biographies and private data sit right next to each other. The defense official said a small number of unauthorized users had accessed personally identifiable information. After discovering it, the agency had supposedly fixed the vulnerability. There was no evidence so far that the data had been misused. What else are they supposed to say?

That sounds unsettling, but in the days of the Trump regime, also familiar. Unauthorized users had access to the system for around 9 months. The information about what jobs military personnel and civilian employees performed goes well beyond ordinary identity theft. If you know someone's role, you can trace relationships. If you also have a Social Security number, you are already holding a small jackpot. The incident can therefore also raise national security concerns. A personnel file can become a map of an apparatus for a foreign intelligence service. The Pentagon is offering those affected identity theft protection and credit monitoring. There is not much more that can be recovered after a breach like this. A Social Security number does not get a new life just because an agency later sends out a warning letter. Data ages more slowly than excuses. The incident became public last week, but only now is the scale becoming visible.
At the same time, the FBI is dealing with a breach of its FBIJobs.gov application portal. On Friday, the bureau informed its employees about the incident. A threat actor had announced plans to publish data belonging to FBI employees. That reportedly included names and home addresses. Personal and work contact information would be included as well. Social Security numbers and dates of birth are also said to be affected. Even emergency contact information was reportedly involved, according to people familiar with the matter. The bureau is therefore operating as if the personal data of all FBI employees had been compromised. The affected portal was reportedly classified as unclassified. The first employees are now being informed that their data was affected. More internal briefings are expected to follow. The warning is brief: stay alert and do not answer suspicious calls. Employees were also advised not to speak to the media. If members of the media trespass on property, employees were told to call 911.
On Monday, the hacking group ShinyHunters spoke out. It claimed that, contrary to its earlier announcements, it no longer intended to publish the data. The operation had supposedly not been about extortion, nor had ransom been demanded. It had not been financially motivated either. Instead, the group said it had used a publicity campaign to protect its own business and fight misinformation. Had it simply said so normally, the group claimed, its message would never have received this much attention. The claims have not been independently verified. At the FBI, it therefore remains unclear how many people were actually affected and what data really ended up in someone else's hands. At the Pentagon, the scale is known. It is now also clear that unauthorized access was possible for months. The Defense Department emphasizes that there is no evidence so far that the information has been misused. That is an important finding, if it is true. A data record does not disappear just because nobody uses it immediately.
2 security breaches have now hit 2 institutions at the same time whose daily work depends on confidentiality. At the Pentagon, more than 3 million people are affected if the deceased are included. At the FBI, the incident is being handled as if practically the entire workforce may have been affected. Right where the government is supposed to protect others and detect threats, employees now have to watch out for suspicious calls themselves.
Nearly 3 million living and deceased people have had to learn that one of the country's most powerful security institutions, at least before Trump, was unable to adequately protect their personal data for months. At the FBI, meanwhile, part of the response is: do not answer suspicious calls and call 911 if members of the media trespass. The Pentagon protects weapons and guards secrets. When it came to its own personnel files, the door stood open long enough.
To be continued ...
Updates – Kaizen News Brief
Alle aktuellen ausgesuchten Tagesmeldungen findet ihr in den Kaizen Kurznachrichten.
To the Kaizen News Brief In English