Pentagon Personnel Agency Breach Exposes Data of 3 Million Individuals
What Happened — Attackers exploited a vulnerability in the Defense Manpower Data Center (DMDC) file‑sharing server, gaining unauthorized access for roughly nine months (Oct 2025 – Jul 2026). The server stored unencrypted personal information, resulting in exposure of 2.76 million living and 294 k deceased individuals’ PII, including SSNs, names, DOB, and military details.
Why It Matters for Trust & Control Assurance
- Continuous access‑control monitoring could have flagged the prolonged, anomalous access to sensitive files.
- Encryption‑at‑rest and strict privileged‑account governance are core controls that generate defensible audit evidence under federal frameworks.
- Rapid, documented incident‑response processes are essential for meeting NIST RMF requirements and maintaining a trustworthy posture.
Who Is Affected
- U.S. Department of Defense personnel, retirees, veterans, contractors, and their families.
Recommended Actions
- Conduct an immediate review of privileged‑account permissions on all file‑sharing platforms.
- Apply encryption at rest for any repository containing PII.
- Deploy continuous monitoring and alerting for anomalous file‑access patterns.
- Update incident‑response playbooks to capture evidence required for NIST RMF audit readiness.
Source: Security Affairs
Technical Notes
- Attack vector: exploitation of an unpatched vulnerability in a file‑sharing system (VULNERABILITY_EXPLOIT).
- Data types exposed: Social Security numbers, names, dates of birth, contact information, race, sex, and military occupational specialties.
- No ransomware or extortion reported; the breach was discovered via internal security monitoring.
Source: same as above