The U.S. Department of Defense is notifying current and former military personnel, civilian employees and related individuals following a cybersecurity incident involving records managed by the Defense Manpower Data Center (DMDC).
According to the DMDC, unauthorized users accessed an unspecified file-sharing system by exploiting a security weakness over several months, from October 2025 to mid-July 2026. The incident involved personal records that may have included names, dates of birth, Social Security numbers and selected military service details.
Identity systems under the spotlight
The DMDC is a central records and identity-management unit within the Department of Defense. It supports access, benefits and eligibility processes for military personnel, civilian staff, contractors and families, managing more than 60 million records across its systems.
Officials said the event may affect approximately 2.8 million living individuals, alongside records associated with nearly 300,000 deceased people. The Department of Defense stated that it has not identified evidence indicating misuse of the affected information.
The case highlights the growing importance of secure digital identity infrastructure in large public institutions. Modern identity systems increasingly depend on continuous vulnerability monitoring, encrypted data environments, multi-factor authentication and rapid incident response procedures.
As organizations expand connected personnel services, this development is likely to accelerate investment in resilient identity technologies designed to protect sensitive records while improving secure access for millions of users.