New Delhi. A security breach involving a US Defence Department personnel database has exposed sensitive personal information linked to nearly 3 million people, including military personnel, civilian employees and others associated with the US defence establishment. According to US defence officials, the incident affected information belonging to 2.76 million living people and around 294,000 deceased individuals.
The exposed information included Social Security numbers and details about jobs held by military and civilian personnel. The nature of the information has raised concerns about possible national security implications. However, officials have said there is currently no evidence indicating that the exposed information has been misused.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
According to defence officials, unauthorised access to the database occurred between October 2025 and July 2026. The security vulnerability was discovered in July and subsequently fixed. A small number of unauthorised users had gained access to personally identifiable information stored in the defence personnel system. Once the vulnerability was identified, immediate steps were taken to address it.
The database is part of the US Defence Department’s personnel management system and contains a large volume of records relating to military and civilian personnel. Its records cover active-duty service members, reserve personnel, civilian employees, contractors, retirees, veterans and military family members. The system reportedly contains more than 60 million personnel records.
Identity protection and credit monitoring services are being offered to people whose information was affected. Officials have maintained that there is no evidence so far that the compromised information has been misused. However, given the sensitive nature of the data, affected individuals have been advised to remain alert.
The Pentagon-related data breach comes as the Federal Bureau of Investigation (FBI) is also dealing with a separate data leak involving its jobs website. A cyber group claimed that it had gained access to personal information belonging to FBI employees.
The information allegedly exposed in the separate incident could include employees’ names, home addresses, personal and official contact details, Social Security numbers, dates of birth and emergency contact information. The FBI has begun responding to the incident on the assumption that personal information of its employees may have been compromised.
Employees whose information may have been affected are being notified about the incident. The agency has also indicated that the system involved in the breach was not a classified system containing sensitive national defence information.
The cyber group that claimed responsibility for the FBI-related data leak later said it would not publish the allegedly obtained information. The group claimed that its objective was not financial extortion but a campaign aimed at promoting its business. However, the claims regarding access to the data, the amount of information obtained and its potential use remain subject to investigation.
The FBI has advised potentially affected employees to remain cautious about suspicious phone calls and other forms of contact. Internal briefings are also expected to be organised for employees affected by the incident.
The two incidents have renewed concerns over the protection of sensitive personal information held by US government institutions. In the Pentagon-related case, personnel records involving millions of people were affected by unauthorised access, while the separate FBI incident involves claims of access to personal information belonging to employees of a federal investigative agency.
Investigations into both incidents are continuing, with authorities examining the security vulnerabilities involved, the extent of the affected information and whether any of the data has been misused. Further details are expected to emerge as the investigations progress.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics