Nine months inside a Pentagon personnel database, and 3 million people to tell
The hole was open from October 2025 until July 2026. The Defense Manpower Data Center, which holds records on more than 60 million serving troops, reservists, civilian staff, contractors, retirees, veterans and their families, has confirmed that unauthorised users reached files on more than 3 million of them through a flaw in a file-sharing system. Roughly 2.76 million living people, and 294,000 who have died.
What sat in those files: names, contact details, dates of birth, military job specialities and Social Security numbers, the last of those held without encryption. The vulnerability was found and patched on 16 July. Notification letters are going out now with twelve months of credit monitoring through IDX attached, and the Pentagon says there is no evidence so far that any of it has been misused.
That last sentence appears in almost every breach notice ever written, and it is usually accurate on the day it is sent. The trouble arrives later. Records of this shape are the raw material for the phone calls that actually work, the ones where the caller already knows your date of birth, your old posting and the last four digits of a number you have never read aloud to a stranger. Knowing those details proves nothing, and that is the assumption worth unlearning.
If a letter lands, take the credit monitoring, and think about freezing your credit file as well, which costs nothing and stops new accounts being opened rather than just telling you about them afterwards. None of this happened on your PC, but the accounts you sign into from it are usually where the knock-on shows up, and Tendvane's privacy and accounts check is a quick way to see which ones are signed in there and how well they are protected.