Pentagon Defense Manpower Data Center (DMDC) Data Breach Exposes Social Security Numbers and Personal Information of 3,054,000 People
A data breach involving the Defense Manpower Data Center (DMDC) exposed personal information belonging to 3,054,000 people, according to a Defense Department spokesperson cited in reporting on September 29, 2026. The affected group reportedly includes 2.76 million living people and 294,000 deceased people. The exposed information included Social Security numbers and, depending on the person, other identifying or military personnel details.
Unauthorized access to a vulnerable DMDC file-sharing system happened between October 2025 and July 16, 2026. DMDC found the vulnerability on July 16, patched the system and restored it. The Defense Department says it has found no evidence so far that the information has been misused.
This is a data breach, not a filed lawsuit. There is no verified claim form, settlement or court case as of September 30, 2026.
Pentagon DMDC Data Breach Quick Facts
| Detail | Information |
| Organization | Defense Manpower Data Center (DMDC), U.S. Department of Defense |
| Reported affected population | 3,054,000 people |
| Living individuals | 2.76 million |
| Deceased individuals | 294,000 |
| Unauthorized access period | October 2025 through July 16, 2026 |
| Vulnerability discovered | July 16, 2026 |
| System involved | DMDC file-sharing system |
| Information exposed | Social Security numbers and other identifying or military personnel information |
| Encryption | Notification information reviewed by defense officials described the affected data as unencrypted |
| Response | Vulnerability patched; system restored; affected people being notified |
| Credit monitoring | One year of credit monitoring and identity restoration through IDX, per reporting on the notification |
| Evidence of misuse | None reported by the Defense Department |
| Lawsuit | None verified as of September 30, 2026 |
| Claim form or settlement | None |
The 3,054,000 total is the sum of 2.76 million living and 294,000 deceased individuals reported from a Defense Department spokesperson. The individual notification letters do not give a total.
How Did the Defense Manpower Data Center Breach Happen?
DMDC is a Department of Defense organization that holds personnel, identity and authentication information across the department. The breach involved a file-sharing system, not a public consumer website.
According to the DMDC notification described in September reporting, DMDC discovered a security vulnerability on July 16, 2026. Its analysis then found that a small number of unauthorized users accessed files on a server containing personally identifiable information between October 2025 and that date. Public information doesn’t identify the unauthorized users or say what they did with the files. Access over a long period does not by itself show how many files were viewed, copied or used.
What Information Did the DMDC Data Breach Expose?
The exposed information varied by person. For the recipient whose September 18 letter was reviewed by reporters, it included a Social Security number and at least one other identifier. Possible additional information includes:
- Name
- Date of birth
- Contact information
- Sex
- Race
- Military personnel information, including occupational specialty
A Social Security number combined with other identifying details can create risks of identity theft, fraudulent accounts and convincing phishing messages. For more on how stolen numbers get misused, see How Can Social Security Identity Theft Occur?
Who Was Affected by the Pentagon DMDC Data Breach?
DMDC’s records reach well beyond active-duty service members. The Defense Department uses DMDC systems for information on military personnel, civilian employees, contractors, retirees, veterans and family members. Getting a DMDC notice does not necessarily mean you currently serve. Your letter is the best source for why your information was included.
What Should DMDC Data Breach Victims Do Now?
- Read your DMDC letter carefully to see what information was involved.
- Enroll in the free monitoring if the letter offers it, using the contact details in the letter itself, not an unsolicited email, text or call.
- Place a fraud alert or credit freeze with Equifax, Experian and TransUnion. Freezes are free.
- Check your credit reports and financial accounts for activity you don’t recognize.
- Watch for phishing. A breach with Social Security numbers and military details can make scam messages more convincing.
- Keep records. Save your notification letter and any documents showing actual identity theft or financial loss in case a compensation process is set up later.

Is There a Lawsuit Over the Pentagon DMDC Data Breach?
No lawsuit has been independently verified in the court records searched as of September 30, 2026. The law firm Migliaccio & Rathod LLP has announced a DMDC data breach investigation and is seeking information from potentially affected people. A law firm investigation is not a filed lawsuit or a certified class action.
| Court | Case number | Parties | Status |
| No verified court case as of September 30, 2026 | Not applicable | None verified | Investigation stage |
If a complaint is filed, the case name, court, case number and claims will need to be verified from the filing before the matter is described as a lawsuit or putative class action.
Is There a Claim Form for the Pentagon DMDC Data Breach?
No. There is no verified settlement claim form or settlement administrator for this incident. Don’t pay anyone to file a claim or give personal information to an unofficial website that mentions the Pentagon breach. The reported response is direct notification plus one year of credit monitoring and identity restoration through IDX.
Pentagon DMDC Data Breach Key Dates
| Date | Event |
| October 2025 | Reported start of unauthorized access |
| July 16, 2026 | DMDC discovers the vulnerability and patches the affected system |
| September 18, 2026 | Date of an individual breach notification reviewed by reporters |
| September 2026 | Public reporting of the breach |
| September 29, 2026 | Defense Department spokesperson gives affected-population figures |
| Current | No verified lawsuit, claim form or settlement |
Frequently Asked Questions About the Pentagon DMDC Data Breach
Did the Pentagon DMDC data breach expose Social Security numbers?
Yes. The DMDC notification information reported in September says the affected files contained Social Security numbers.
How many people were affected by the DMDC data breach?
The reported figure is 3,054,000 people: 2.76 million living individuals and 294,000 deceased individuals, attributed to a Defense Department spokesperson.
When did unauthorized access occur in the DMDC breach?
From October 2025 through July 16, 2026, when DMDC discovered the vulnerability.
What information was exposed in the DMDC breach?
It varied by person. Reported categories include Social Security numbers, names, dates of birth, contact information, sex, race and military personnel information such as occupational specialty.
Was the DMDC breach limited to current military members?
No. DMDC systems cover military personnel, civilian employees, contractors, retirees, veterans and family members.
Has the DMDC data breach led to identity theft?
The Defense Department says there is no evidence of misuse so far. That does not mean misuse can’t happen later.
Is there a DMDC data breach settlement or class action?
No settlement or filed class action has been verified as of September 30, 2026. A law firm has announced an investigation, which is not a court case.
Can DMDC breach victims file a claim for money?
No public compensation claim process exists at this time. Keep your notification letter and records of any losses.
What Happens Next in the Pentagon DMDC Data Breach?
DMDC is continuing to notify affected people and has patched the vulnerable system. Open questions include the identity of the unauthorized users and how much of the exposed data was actually accessed. A lawsuit could be filed later, but there is no complaint to analyze now. If one is filed, the complaint will show what claims are made. For now, confirm what your letter says, use the offered protection services, monitor your accounts and credit, and watch for phishing.
Important: This article is general information, not legal advice. AllAboutLawyer.com is not a law firm. Breach details can change as the Defense Department completes its investigation and notifications.
Sources
- Pentagon breach exposed sensitive data on nearly 3 million people (ABC News)
- Military personnel data exposed in breach, agency warns (Navy Times, September 24, 2026)
- Defense Manpower Data Center Data Breach Investigation (Migliaccio & Rathod LLP)
- Defense Manpower Data Center incident record (Cyber Security Incident Database)
- Personnel Readiness Management Agency, Department of Defense
Researched and written by Israr Ahmad, legal content researcher and founder of AllAboutLawyer.com. All facts checked against news reporting on the Defense Department’s statements and the DMDC breach notification, and a review of court records for any filed case, as of September 30, 2026. A public copy of the notification letter itself was not available. Last Updated: September 30, 2026.
About the Author
Israr Ahmad is a legal content researcher with 4+ years of experience covering class action settlements and consumer rights cases. He has researched and published coverage of 2,500+ settlements using verified court records, settlement administrator filings, and government sources. Learn more about Israr.
