The US Defense Manpower Data Center has begun telling people their personal information was exposed, in a breach that touches roughly 3 million individuals.
A notification letter dated September 18 says unauthorized users reached one of the center’s file-sharing servers for about nine months. A vulnerability in that system was found on July 16, 2026, and patched the same day.
“Analysis identified that between October 2025 and the date of discovery, a small number of unauthorized users accessed files on a server containing unencrypted PII,” the letter reads. The affected product and the nature of the flaw were not disclosed.
The center maintains personnel records for the Pentagon, spanning service members, civilians, contractors, family members, retirees and veterans. Its own site counted more than 60 million records as of fiscal year 2024.
No known cybercrime group has claimed the intrusion. The center says it stood up privacy and incident response actions once the flaw was found, and the letter does not describe whether the exposed data has surfaced elsewhere.
