It has been revealed that over 3 million records in a personnel database managing personal information for U.S. military personnel may have been accessed externally. U.S. ABC News reported on September 28 that unauthorized access occurred at the U.S. Department of Defense's (DoD) Defense Manpower Data Center (DMDC) between October 2025 and July 2026.

According to the report, DoD officials stated that the number of affected individuals totals approximately 3.05 million, comprising 2.76 million living individuals and approximately 294,000 deceased individuals. A notification letter for affected individuals, confirmed by military and defense media outlet Military Times, indicates that files containing unencrypted personally identifiable information were accessed through a vulnerability in a file-sharing system.

The compromised information may include names, Social Security numbers, dates of birth, contact information, as well as job-related details for military personnel and civilian employees. The DMDC discovered and patched the vulnerability on July 16, 2026. DoD officials stated that there is currently no evidence that the information has been misused.