WASHINGTON — A severe cybersecurity breach at the Department of Defense’s Defense Manpower Data Center (DMDC) has exposed the Social Security numbers, job details, and sensitive personal information of nearly 3 million individuals. Unauthorized actors maintained undetected access to the sensitive database for approximately 10 months before the intrusion was discovered. The breach impacts a total of 3.05 million people, comprising 2.76 million living individuals alongside 294,000 deceased records.
The compromised database serves as the primary centralized repository for the Pentagon’s personnel data, maintaining over 60 million records across active-duty service members, National Guard and Reserve personnel, military retirees, Department of Defense civilian employees, and defense contractors. The exposure of high-level career histories and Social Security numbers poses significant counterintelligence, identity theft, and personal security risks, prompting immediate forensic audits, network access revocations, and system-wide hardening across the Department’s personnel data infrastructure.
TECHNICAL SPECIFICATIONS: DEFENSE MANPOWER DATA CENTER (DMDC) INFRASTRUCTURE & BREACH DATA
* Target Organization: Defense Manpower Data Center (DMDC) / Office of the Under Secretary of Defense for Personnel and Readiness
* Total Records Compromised: ~3.05 million total individuals
* Living Personnel Impacted: 2.76 million individuals
* Deceased Personnel Impacted: 294,000 individuals
* Total Database Holding Capacity: Exceeds 60 million active and historical personnel records
* Dwell Time / Intrusion Duration: Undetected unauthorized access sustained for approximately 10 months
* Compromised Data Sets: Social Security Numbers (SSNs), duty stations, job assignment histories, personal contact details, and military administrative records
* Core DMDC Operational Functions:
* Manages the Defense Enrollment Eligibility Reporting System (DEERS)
* Administers Common Access Card (CAC) and identity credential verification frameworks
* Tracks active, reserve, veteran, civilian, and dependent benefits eligibility across all service branches
* Remediation & Forensic Countermeasures: Network segment isolation, credential reset protocols, implementation of enhanced zero-trust architecture, and credit monitoring provisioning for affected personnel