Hackers stole millions of US military personnel records during months-long data breach
- ID
- 30482
- Status
- summarized
- Published
- 01 Oct 2026, 3:29 AM
- Fetched
- 01 Oct 2026, 4:26 AM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/09/30/hackers-stole-millions-of-us-military-personnel-records-during-months-long-data-breach/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 3.0
- Created
- 01 Oct 2026, 4:27 AM
- Tags
- Audience
- developersstartup_founders
What happened
A Defense Manpower Data Center (DMDC) breach notification shared on Reddit says unauthorized users exploited a vulnerability in an unspecified file-sharing system over roughly nine months, from October 2025 to mid-July 2026, exposing unencrypted personnel records. CNN and Federal News Network report a Pentagon official put the count at about 2.8 million living people plus nearly 300,000 deceased, with Social Security numbers, names, dates of birth, sex, race, and military service details exposed. DMDC holds over 60 million records and acts as the military's identity management provider linking people to smart cards and passwords for Pentagon systems and bases.
Why it matters
The stolen records were unencrypted and sat in a file-sharing system for months before detection — the same pattern any team running internal HR, payroll, or identity files faces. If your org (including Malaysian employers handling staff data under PDPA) moves personnel exports through shared drives or third-party file transfer, the concrete action is to check whether those stores are encrypted at rest and whether access logs would have shown a nine-month exfiltration. Nothing in this item is specific to Malaysia, AI, or developer tooling, so it is background context rather than something that changes your stack this week.
Discussion angle
The breach ran from October 2025 to mid-July 2026 before notice — what logging or alerting would have caught a nine-month read pattern in your own file-sharing or HR data pipeline, and is that data encrypted at rest today?