Skip to content

Security2 publishers2 min readPublished

Pentagon personnel agency discovered the file-server flaw nine months after intruders began using it

Defense Manpower Data Center is notifying people after intruders read unencrypted files on its server for nine months, exposing 2.76 million living people. Nine months of access means every file that server held over the period should be treated as copied.

The Watch · Security desk

Photograph accompanying Pentagon personnel agency discovered the file-server flaw nine months after intruders began using it
Photo: abcnews.com

What happened

  • A Department of War official told CNN that 294,000 deceased people are also affected, a count that does not appear in DMDC's own letter.
  • In the letter one recipient shared, the exposed data included a Social Security number and at least one other identifier, such as name, birth date, contact details, race or military specialty.
  • DMDC says the Department of War has no indication so far that the accessed information has been misused.
  • DMDC is offering 12 months of free credit monitoring through IDX, with enrollment open until August 19, 2027.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Whoever holds copies can contact each person directly and build a phishing pretext around their real military job, a risk that sits outside the credit misuse the IDX monitoring is meant to catch.
  • constraint Other agencies and companies running file-sharing servers cannot check for the same flaw until the product or the vulnerability is named.
  • constraint Defense contractors cannot tell from public reporting whether their staff are among the 2.76 million; for now only the individual letters answer that.

DMDC's letter puts the flaw first and the intruders second. It says a vulnerability in a DMDC file-sharing system was found on July 16, 2026, and that "DMDC immediately updated the file sharing system to patch the vulnerability and the system was restored" [6]. Only after that does it report that "a small number of unauthorized users accessed files on a server containing unencrypted PII," with access going back to October 2025 [7]. Depending on when in October it began, the window ran roughly 8.5 to 9.5 months [3].

Those few users reached a lot of people. Counting the deceased, the figures a Department of War official gave CNN add up to about 3.05 million [1]. That count comes from one unnamed official [2]. CNN reported that the official described the living group as potentially including current and former defense personnel or their dependents [4]. DMDC's holdings are far wider: at least 60 million records as of fiscal 2024, covering military and civilian personnel, contractors, family members, retirees and veterans [12].

The copy of the letter that is now public was posted by a recipient. It is dated September 18 [9], 64 days after the flaw was found [2]. DMDC says it is still assessing the affected system and taking steps to improve its security [15].

The letter does not name the file-sharing product or describe the vulnerability [10]. No known cybercrime group appears to have taken credit, and it is unclear who is behind the attack [13]. On the public record this is one intrusion at one agency, with no named actor or tool that would tie it to a campaign. If the flaw is in a commercial product, that product's other operators had the same opening until a fix reached them.

What to watch

  • DMDC or the Department of War naming the file-sharing product or the vulnerability, so other operators can check their own servers.
  • A group claiming the intrusion, or DMDC records turning up for sale, would tie this to an actor and end the single-incident read.
  • Any change to the Department of War's statement that it has no indication of misuse, or a revised count once DMDC finishes assessing the system.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories