Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Pentagon Personnel Agency Breach Exposes Data of 3 Million Individuals

A vulnerability in the Defense Manpower Data Center’s file‑sharing system allowed unauthorized users to access unencrypted personal records for nine months, affecting 2.76 million living and 294 k deceased individuals. The incident underscores the need for robust access‑control, encryption, and continuous monitoring to satisfy federal audit and risk‑management expectations.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
securityaffairs.com

Pentagon Personnel Agency Breach Exposes Data of 3 Million Individuals

What Happened — Attackers exploited a vulnerability in the Defense Manpower Data Center (DMDC) file‑sharing server, gaining unauthorized access for roughly nine months (Oct 2025 – Jul 2026). The server stored unencrypted personal information, resulting in exposure of 2.76 million living and 294 k deceased individuals’ PII, including SSNs, names, DOB, and military details.

Why It Matters for Trust & Control Assurance

  • Continuous access‑control monitoring could have flagged the prolonged, anomalous access to sensitive files.
  • Encryption‑at‑rest and strict privileged‑account governance are core controls that generate defensible audit evidence under federal frameworks.
  • Rapid, documented incident‑response processes are essential for meeting NIST RMF requirements and maintaining a trustworthy posture.

Who Is Affected

  • U.S. Department of Defense personnel, retirees, veterans, contractors, and their families.

Recommended Actions

  • Conduct an immediate review of privileged‑account permissions on all file‑sharing platforms.
  • Apply encryption at rest for any repository containing PII.
  • Deploy continuous monitoring and alerting for anomalous file‑access patterns.
  • Update incident‑response playbooks to capture evidence required for NIST RMF audit readiness.

Source: Security Affairs

Technical Notes

  • Attack vector: exploitation of an unpatched vulnerability in a file‑sharing system (VULNERABILITY_EXPLOIT).
  • Data types exposed: Social Security numbers, names, dates of birth, contact information, race, sex, and military occupational specialties.
  • No ransomware or extortion reported; the breach was discovered via internal security monitoring.

Source: same as above

📰 Original Source
https://securityaffairs.com/200017/uncategorized/three-million-affected-in-pentagon-personnel-agency-data-breach.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →