NEWS
Stolen Military Job Codes Outlive a Year of Credit Monitoring
A nine-month DMDC file-share breach exposed SSNs and military job codes for 3.054 million people. A year of credit monitoring cannot recall that targeting data.
A Pentagon personnel agency says outside users spent nine months on a file-sharing server that held unencrypted records for 2.76 million living people. Social Security numbers sat beside names, birth dates, contact details, and military job codes. The Defense Manpower Data Center found the flaw on July 16, 2026, and mailed notices dated September 18.
The department is offering 12 months of credit monitoring through IDX. That offer treats the dump as consumer fraud. A job code paired with an SSN is also a map of who does what in the force, and a year of alerts does not pull that map back.
Nine Months on an Unencrypted File-Sharing Server
DMDC is the Pentagon’s personnel-data agency, set up in 1974 to keep manpower, training, and benefits files on troops, civilians, contractors, families, retirees, and veterans. A notice dated September 18, later posted by a recipient and confirmed by defense officials, describes a security flaw in a DMDC file-sharing system. The letter does not name the product or the flaw.
On July 16, 2026, a security vulnerability in a DMDC file sharing system was discovered, which allowed unauthorized users to access files. DMDC immediately updated the file sharing system to patch the vulnerability and the system was restored.
Defense Manpower Data Center, September 18, 2026 notification letter
Analysis after the patch found that a small number of unauthorized users had reached a server of unencrypted personally identifiable information between October 2025 and the July 16 discovery. The department says it then opened privacy and cybersecurity incident response under Office of Management and Budget rules. Pentagon spokesperson Susan Gough later confirmed the size of the affected group in an emailed statement. A Pentagon official declined to say who the users were, whether a particular group was targeted, whether the intrusion was intentional, or why the files sat unencrypted.
THE ACCESS WINDOW
- October 2025: Unauthorized users first reach the file-sharing server, per the DMDC letter.
- July 16, 2026: DMDC finds the flaw, patches the system, and restores it.
- September 18, 2026: The dated notice goes to at least one person whose Social Security number was in the files, 64 days after discovery.
- August 19, 2027: Deadline to enroll in the 12 months of IDX credit monitoring tied to the notice.
The letter says users “accessed” files. It does not say the files were copied off the server, sold, or published, and no group has claimed the intrusion. “Accessed” is the working fact. Anything beyond that is still unconfirmed.
Occupational Specialty Turns a Stolen SSN Into a Targeting List
Each notice says the recipient’s Social Security number was exposed with at least one other identifier. That extra field can be a name, date of birth, contact information, sex, race, or military personnel information, including occupational specialty. The mix varies by person. The specialty field is the one a credit bureau cannot lock.
A military occupational specialty is the job code that says what a service member is trained to do. Army intelligence work sits in codes such as 35F for an all-source analyst and 35N for a signals analyst. Marine Corps files use codes such as 0211 for counterintelligence and human intelligence work, a specialty the Corps has called a critical shortage and has paid large reenlistment bonuses to fill. Pair that code with an SSN, a birth date, and a phone number, and an adversary has a name, a function, and a way to reach the person.
National security specialists have already flagged the dump as a counterintelligence problem, not only a fraud problem. Retired Lt. Gen. Russel Honoré, who commanded the Katrina relief task force, asked in public whether China or Iran was behind it. The department has named no actor. The targeting value does not depend on that answer. A phishing note that cites a real job code, a real rank, or a real unit looks like official traffic, which is how follow-on access to mail, benefits portals, and building systems usually starts.
People who received the letter and then posted it, a last-four SSN, or a command name on public forums made that follow-on work easier. The notice is a warning. It is also a template if the envelope itself becomes a screenshot.
2.76 Million Living People and 294,000 Dead
Two people familiar with the incident initially put the figure at about 4 million Defense Department personnel. A Pentagon official later gave a split count: 2.76 million living people and 294,000 deceased, a combined 3.054 million. The living group can include current and former defense personnel and their dependents. The dead count is not a footnote. Death records still carry SSNs and service histories that fraud rings reuse, and they still describe people who held sensitive jobs.
THE OFFICIAL COUNT
| Group | Count | Where the figure comes from |
|---|---|---|
| Living people | 2.76 million | Pentagon official |
| Deceased people | 294,000 | Pentagon official |
| Combined affected | 3.054 million | Sum of the official split |
| DMDC person archive | More than 60 million | DMDC FY24 fast facts |
The 3.054 million is a slice of a much larger store. DMDC’s own overview lists more than 60 million person records for fiscal year 2024, covering military members, civilians, contractors, family members, retirees, and veterans. The same page says the center supports identity checks for ID cards and base access at thousands of sites. The notice does not say which slice of that archive sat on the open server, or whether the users could see more than they opened.
Troops were already a richer fraud target than other adults before this letter went out. Five years of IdentityTheft.gov filings, studied by FTC analyst Emma Fletcher, show active-duty service members are 76 percent more likely than other adults to report that a thief misused an existing account, and nearly three times as likely to report a debit-card or electronic raid on a bank account. They are 22% more likely to report a new account opened in their name. Many of those reports also warn that bad credit can follow a clearance file.
What the September 18 Letter Offers Recipients
The mailed notice is the only detailed public account the department has put in writing. There was no news release on the DMDC site as of the last days of September. Recipients are being reached by postal mail through Identity Theft Guard Solutions, the IDX contractor on the account, which the department says will scale credit monitoring and identity restoration to the data fields hit in each case. Questions are being routed to IDX at 1-855-744-4556 and at response.idx.us/DMDC.
FIELDS NAMED IN THE LETTER
- Social Security number: Named for the recipient whose notice was reviewed, and listed as the common identifier in the exposed set.
- Name and date of birth: Listed among the extra fields that may travel with the SSN.
- Contact information: Phone, address, or other reach-back data, varying by file.
- Sex and race: Demographic fields the letter groups with other personal details.
- Occupational specialty: The military job code, when that personnel field is present.
The letter’s reassurance is narrow. “At this time, DoW does not have any indications of misuse of the accessed information,” it says. That clause does not establish whether copies left the server, and it does not speak to use that has not yet been spotted. The department also wrote that it is “taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system,” without saying what those actions are.
The 2015 OPM Theft Took 21.5 Million Background Files
This is not the first time a U.S. personnel agency has lost identity files at scale. In 2015 the Office of Personnel Management disclosed two related incidents. One took personnel data on 4.2 million current and former federal employees. The second, announced after a forensic review, took sensitive information including Social Security numbers from 21.5 million background investigation files, a set that covered 19.7 million people who had applied for a background check and 1.8 million non-applicants, mostly spouses or cohabitants. Fingerprint counts in that case later rose to 5.6 million.
Those 2015 files included residency and education history, family names, and interview notes from clearance forms. The DMDC dump is smaller and thinner. It is also closer to the operational force, because occupational specialty is a present-tense job label, not a decade-old investigation narrative. The 2015 theft was widely tied to China. Honoré’s question about China or Iran sits in that memory, and it is still a question. DMDC has not said the two events are linked.
The remedy rhyme is the part that repeats. After OPM, the government bought years of monitoring through ID Experts, later IDX. After this letter, the same vendor is back on a 12-month clock. Monitoring watches credit files for new accounts. It does not change a job code that has already left the building, and it does not stop a tailored email that already knows the recipient’s specialty.
A Credit Freeze Outlasts the IDX Offer
IDX enrollment runs through August 19, 2027, and the coverage itself is 12 months. A Social Security number does not expire on that date. The Federal Trade Commission’s longer-lived tool is a free credit freeze placed with Equifax, Experian, and TransUnion. While the freeze is on, no one, including the account holder, can open a new credit account in that name. It does not change a credit score. It lasts until the person lifts it, which can be done for a single bureau when a lender needs a check.
TOOLS THAT OUTLAST 12 MONTHS
- Credit freeze: Place it at all three bureaus; it stays until you lift it, and it is free.
- Initial fraud alert: Contact one bureau and the other two are told; it lasts one year and can be renewed.
- Active duty alert: Available to active-duty members, lasts one year, and can be renewed for a deployment; it also drops the name from some credit-offer lists for two years.
- Child freeze: A parent can freeze a file for a child under 16, which matters if dependents were in the DMDC set.
Active-duty members and National Guard members can also get free electronic credit monitoring from each bureau, separate from the IDX year. None of those steps recovers a job code, a birth date, or an SSN that an outsider already read. They make new credit harder to open, which is the fraud half of the harm. They do nothing to the intelligence half, and they do not stop a caller who already has the file and only needs a password.
The File-Sharing Product Still Has No Public Name
The letter’s silences are now the live facts. The product on the file-sharing server has no public name. The flaw has no public identifier. The users have no public identity. The department has not said whether any file was copied, and it has not said why unencrypted PII was on that server at all.
WHAT WE KNOW
- The window: Unauthorized access ran from October 2025 to July 16, 2026, on a DMDC file-sharing system.
- The count: A Pentagon official put the living total at 2.76 million and the deceased total at 294,000, or 3.054 million combined.
- The fields: Social Security numbers plus at least one other identifier, which can include occupational specialty.
- The offer: 12 months of IDX monitoring, with enrollment due by August 19, 2027.
WHAT IS UNCONFIRMED
- The product: No file-sharing vendor, version, or flaw identifier has been released.
- The users: No criminal group or state actor has been named, and no one has claimed the intrusion.
- The copies: Officials have not said whether files left the server or only were opened in place.
- The misuse: “No indications” is a present finding, not a finding that the data is inert.
The patch closed one server on July 16. The notices started reaching mailboxes in September. The SSNs and job codes that were sitting on that server do not reset when IDX coverage runs out, and the department has not said they never left.
-
AUTO4 weeks agoVolkswagen Sells the Osnabruck Plant to Clear a Board Fight
-
AUTO1 month agoTata Motors’ Iveco Tender Opens as Holders Still Decide
-
BUSINESS1 month agoSaksham Gaur Finds He Is His Own Company’s Client
-
GAMING1 month agoOnimusha Way of the Sword Preload Hits a Windows 11 Wall
-
NEWS4 weeks agoThe Frame Pro’s $1,200 Labor Day Cut Needs a Soundbar
-
NEWS1 month agoApple’s Foldable iPhone Hinges on Samsung Display Supply
-
BUSINESS4 weeks agoSEBI Reopens How F&O Settles After the Closing Auction
-
BUSINESS1 month agoThe Rs 4.66 Lakh Crore IPO Queue Is Mostly Paper
