Following last week's report on the FBI data breach—where a hacker group claimed to have stolen data from "all FBI employees"—a U.S. Department of Defense official confirmed that the Pentagon also suffered a cybersecurity intrusion. This breach is larger in scale and lasted longer, potentially causing significant concern among many U.S. government civilian employees and active-duty military personnel.
According to ABC News, the official stated: "Between October 2025 and July 2026, the Defense Manpower Data Center (DMDC) information systems were subjected to unauthorized access by a small number of users, resulting in the acquisition of a large amount of personally identifiable information."
The Defense Manpower Data Center is one of the Pentagon's core personnel record databases, storing information on active-duty military, reservists, civilian employees, contractors, and veterans. Statistics show that this breach affected approximately 2.76 million living individuals and around 294,000 deceased persons.
Upon discovering the unauthorized access, the Defense Manpower Data Center "immediately patched the security vulnerability." The leaked data reportedly includes Social Security numbers and detailed information on both military and civilian positions, but Department of Defense officials stated that, so far, there is no evidence that this leaked information has been misused.
The situation could have been worse. The Defense Manpower Data Center is said to store records for over 60 million people, meaning the 3 million affected individuals represent only about one-twentieth of the total records. However, CNN reported that the illegally obtained information includes "occupational specialties" of U.S. military personnel. When combined with Social Security numbers, this data could allow hostile foreign entities to gain a clearer understanding of the deployment and operational objectives of U.S. agents worldwide.
According to media disclosures, the stolen data was not encrypted, making it extremely easy to cross-reference with other previously leaked information. Currently, no hacker group has publicly claimed responsibility for this breach.
Nevertheless, over the past year, hackers have successfully breached two major information fortresses of the U.S. government, which may signal a significant upgrade in their attack capabilities. Will 2026 become a year marked by frequent hacker intrusions into the U.S. government? It seems the answer will be revealed in just a few months.

