Home › Intelligence › Brief
BREACH BRIEF 🟠 High Breach

Pentagon Personnel Agency Breach Exposes Data of 3 Million Individuals

A vulnerability in the Defense Manpower Data Center’s file‑sharing system allowed unauthorized users to access unencrypted personal records for nine months, affecting 2.76 million living and 294 k deceased individuals. The incident underscores the need for robust access‑control, encryption, and continuous monitoring to satisfy federal audit and risk‑management expectations.

Verisq™ Intelligence · 📅 September 29, 2026 · 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
securityaffairs.com

Pentagon Personnel Agency Breach Exposes Data of 3 Million Individuals

What Happened — Attackers exploited a vulnerability in the Defense Manpower Data Center (DMDC) file‑sharing server, gaining unauthorized access for roughly nine months (Oct 2025 – Jul 2026). The server stored unencrypted personal information, resulting in exposure of 2.76 million living and 294 k deceased individuals’ PII, including SSNs, names, DOB, and military details.

Why It Matters for Trust & Control Assurance

  • Continuous access‑control monitoring could have flagged the prolonged, anomalous access to sensitive files.
  • Encryption‑at‑rest and strict privileged‑account governance are core controls that generate defensible audit evidence under federal frameworks.
  • Rapid, documented incident‑response processes are essential for meeting NIST RMF requirements and maintaining a trustworthy posture.

Who Is Affected

  • U.S. Department of Defense personnel, retirees, veterans, contractors, and their families.

Recommended Actions

  • Conduct an immediate review of privileged‑account permissions on all file‑sharing platforms.
  • Apply encryption at rest for any repository containing PII.
  • Deploy continuous monitoring and alerting for anomalous file‑access patterns.
  • Update incident‑response playbooks to capture evidence required for NIST RMF audit readiness.

Source: Security Affairs

Technical Notes

  • Attack vector: exploitation of an unpatched vulnerability in a file‑sharing system (VULNERABILITY_EXPLOIT).
  • Data types exposed: Social Security numbers, names, dates of birth, contact information, race, sex, and military occupational specialties.
  • No ransomware or extortion reported; the breach was discovered via internal security monitoring.

Source: same as above

📰 Original Source
https://securityaffairs.com/200017/uncategorized/three-million-affected-in-pentagon-personnel-agency-data-breach.html ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →