The Pentagon data breach exposed personal records of about 3.05 million people, including 2.76 million living service members, civilians, contractors, retirees, veterans and family members, plus 294,000 deceased individuals. Attackers got in through a flaw in a Defense Manpower Data Center (DMDC) file-sharing system and had access from October 2025 until July 16, 2026. If you got a notice letter, you can claim 12 months of free credit monitoring through IDX.
Below, you’ll find what was stolen, who’s affected, how to tell if you’re on the list, and the exact steps to protect yourself.
| Key fact | Details |
|---|---|
| Agency breached | Defense Manpower Data Center (DMDC) |
| Access window | October 2025 to July 16, 2026 |
| Discovered and patched | July 16, 2026 |
| Notification letters | Dated September 18, 2026 |
| People affected | 2.76 million living + 294,000 deceased (about 3.05 million) |
| Data exposed | SSNs, names, birth dates, contact info, sex, race, job details |
| Free help offered | 12 months of credit monitoring and identity restoration via IDX |
| Attacker | Not identified; no group has claimed it |
What Happened in the Pentagon Data Breach?
The DMDC is the Defense Department’s central source for identifying and verifying personnel. It holds more than 60 million records covering troops, civilians, contractors, retirees, veterans and their families.
What the DMDC actually does
The DMDC collects personnel, manpower, training, financial and other data for the department. That data supports things like healthcare, retirement and day-to-day administration.
In other words, it’s the system that helps confirm who you are when you use many military benefits. That’s why its records are so detailed, and why a leak from it is so sensitive.
How attackers got in
According to the notification letter, a security vulnerability in a DMDC file-sharing system let unauthorized users open files on a server. Those files held unencrypted personal information.
The DMDC found and fixed the flaw on July 16, 2026. By then, the intruders had been able to reach the files for roughly nine months.
How the news came out
The timeline matters because many people heard about it weeks after letters went out:
| Date | What happened |
|---|---|
| October 2025 | Unauthorized access begins |
| July 16, 2026 | DMDC discovers and patches the flaw |
| September 18, 2026 | Notification letters dated and sent |
| September 24, 2026 | Military Times first reports the breach |
| Late September 2026 | Final counts published: 2.76M living, 294,000 deceased |
Early reports, based on unnamed sources, put the number near 4 million. The figures in later coverage, 2.76 million living and 294,000 deceased, are the ones most outlets now use.
Who Is Affected by the DMDC Breach?
Because the DMDC holds records on almost everyone tied to the U.S. military, the affected group is broad. You may be affected if you are or were:
- Active-duty military or a member of the reserves or National Guard
- A civilian employee of the Defense Department
- A defense contractor with records in the system
- A military retiree or veteran
- A family member or dependent of someone above
Records of 294,000 deceased people were also exposed. Families of deceased service members should watch for misuse too, because criminals sometimes use a dead person’s identity for tax or credit fraud.
What Data Was Exposed?
This is a serious breach because of the mix of data involved. Social Security numbers paired with names and birth dates are exactly what identity thieves need.
| Data type | Exposed? | Why it matters |
|---|---|---|
| Social Security number | Yes | Can be used to open credit or file fake tax returns |
| Full name | Yes | Links the SSN to you |
| Date of birth | Yes | Common identity check for banks and agencies |
| Contact information | Yes | Enables targeted phishing calls, texts and emails |
| Sex and race | Yes | Personal demographic data |
| Military job specialty and personnel info | Yes | Can make scams look more convincing |
So far, the department says it has no indication that the information has been misused. But it hasn’t confirmed whether files were copied, so it’s smart to act as if they were.
Who Was Behind the Pentagon Hack?
Nobody knows yet. No group has claimed responsibility, and officials haven’t named a suspect.
This comes in a tough stretch for federal data security. The same week, the FBI disclosed a separate major incident involving applicant data, which we covered in our explainer on the ShinyHunters FBI breach.
Security reporters have also raised national security concerns. Knowing who holds which military job could help foreign intelligence services or scammers target specific people.
How to Know If You’re Affected
The main way to find out is the mailed notification letter. The department says affected people were notified by mail.
If you think you should have received a letter but didn’t:
- Check your mail for a letter dated around September 18, 2026.
- Update your address with your branch or agency if you’ve moved, since letters go to the address on file.
- Visit the official IDX response page at response.idx.us/DMDC for details on the offer.
- Call the IDX support line at 1-855-744-4556 with questions.
Be careful with unexpected calls, texts or emails about this breach. Scammers often pose as “breach support” to steal more details. Only use the phone number and web address above, or those printed in your letter.
What to Do Now: 7 Steps to Protect Yourself
Even if you haven’t received a letter, these steps are worth taking if you have any link to the DoD.
1. Enroll in the free IDX credit monitoring
Affected people get 12 months of credit monitoring and identity-restoration services at no cost. Enroll using the code in your letter. Monitoring alerts you when new accounts or changes show up on your credit report.
2. Freeze your credit at all three bureaus
A credit freeze stops lenders from opening new accounts in your name. It’s free at Equifax, Experian and TransUnion. You can lift it temporarily when you need to apply for credit.
3. Get an IRS Identity Protection PIN
Because SSNs were exposed, tax fraud is a real risk. An IRS IP PIN is a six-digit number that stops anyone else from filing a return with your SSN. It’s free, it’s valid for one calendar year, and the fastest way to get one is through your IRS online account.
4. Use free active-duty credit monitoring
If you’re on active duty or in the National Guard, you can also get free electronic credit monitoring from the credit bureaus.
5. Check your credit reports
Look for accounts, addresses or inquiries you don’t recognize. You can request your free reports by calling 1-877-322-8228.
6. Watch for targeted phishing
With your name, contact details and job role exposed, scammers can write very convincing messages. Watch for anything that references your service, unit or benefits and asks you to “verify” your identity. AI tools make this easier for criminals, as we explained in our look at deepfake-as-a-service.
7. Protect deceased relatives’ identities
If a family member who has died was a service member, notify the credit bureaus and keep an eye out for any mail about new accounts or tax filings in their name.
This step is easy to forget. Deceased people don’t check their credit, so fraud in their name can go unnoticed for a long time. A quick note to each bureau makes their records much harder to abuse.
| Step | Cost | Where to do it |
|---|---|---|
| Enroll in IDX monitoring | Free | Code in your letter, response.idx.us/DMDC |
| Credit freeze | Free | Equifax, Experian and TransUnion separately |
| IRS IP PIN | Free | Your IRS online account |
| Check credit reports | Free | 1-877-322-8228 |
Warning Signs Your Identity Is Being Misused
Monitoring only helps if you know what to look for. Watch for these red flags over the next year and beyond:
- Letters about accounts you didn’t open, such as new credit cards, loans or utility accounts
- A rejected tax return because someone already filed using your SSN
- Debt collection calls about money you don’t owe
- Unexpected credit checks showing up in your monitoring alerts
- Changes to your benefits accounts, such as a new bank account or mailing address you didn’t set
- Messages that know your job or unit and push you to act fast or “confirm” details
If you spot any of these, act quickly. Contact the company involved, use the identity-restoration help that comes with your IDX enrollment, and report it to the Federal Trade Commission at 1-877-438-4338.
What This Means for Service Members and Families
For many people, the hardest part of this breach is that it’s out of their hands. You had to give this information to serve, work or support someone who serves.
The good news is that the tools to protect yourself are free and fairly quick. A credit freeze, an IP PIN and the free IDX monitoring together make it much harder for anyone to turn stolen data into real damage.
It’s also worth talking to family members. Spouses, adult children and older relatives may be on the list too, and they may not have opened their letter yet. Sharing these steps can save someone a lot of trouble later.
If you lead a unit or team, a short reminder about the letters and the IDX offer can help people who missed the news.
Why This Breach Is a Wake-Up Call
The most worrying detail is that the files were unencrypted. Encryption would have made stolen files far less useful.
Large agencies hold decades of records, and every copy sitting on a file server is a target. Strong encryption is the baseline, and it will need to keep evolving as threats grow, which is why post-quantum cryptography is already on security teams’ radar.
For you, the lesson is simple. You can’t control how an agency stores your data, but you can freeze your credit and lock down your tax account so stolen data is harder to use.
Source: IDX’s official DMDC breach response page.
Pentagon Breach: Common Questions
About 3.05 million: 2.76 million living people and records of 294,000 deceased people. Early reports put the figure near 4 million, but later coverage settled on these numbers.
Exposed files held Social Security numbers, names, dates of birth, contact information, sex, race and military job details. The files were stored unencrypted on a DMDC file-sharing server.
Affected people were notified by mail, with letters dated around September 18, 2026. If you’re unsure, check the official IDX page at response.idx.us/DMDC or call 1-855-744-4556.
Yes. Affected people get 12 months of free credit monitoring and identity-restoration services through IDX, a company contracted by the Defense Department.
No one has been identified. No group has claimed responsibility, and officials haven’t named a suspect.
Yes, it’s one of the best steps you can take. A freeze is free at Equifax, Experian and TransUnion, and it blocks new accounts from being opened in your name.
The notification letter says there’s no indication of misuse so far. However, it doesn’t confirm whether files were copied, so taking protective steps now is wise.
