Technology

Hackers Stole Personal Info of Millions Linked to the U.S. Military

Martin HollowayPublished 11h ago2 min readBased on 4 sources
Reading level
Hackers Stole Personal Info of Millions Linked to the U.S. Military
Photo by David B. Gleason from Chicago, IL / CC BY-SA 2.0

About 2.8 million living people and close to 300,000 people who have died are being told their personal information was stolen in a months-long breach of Pentagon personnel records. Outsiders had access from October 2025 to mid-July 2026 through a security hole in a file-sharing system that has not been named. Details were reported on Sept. 30. TechCrunch

Those told are current and former U.S. military service members and staff. The stolen data included names, Social Security numbers, birth dates, sex, race and details about military service, including job types. The records were not encrypted, so they were stored in readable form. The center holds more than 60 million records on military and civilian staff and their families, so the confirmed loss is a small part of the total but still a large number of people. Federal News Network

The Department of Defense said it has seen no sign the stolen information was misused. It is not known who took it. The Pentagon had earlier listed 2.76 million living people and 294,000 deceased people, numbers now replaced by the notification totals. ABC News

The broader context here is about design. A central store of personnel records is a rich target. A file-sharing tool linked to it adds risk, like a side door into a filing room, because it is built to move large amounts of data and often has wide permission to reach files. When records are stored unlocked, getting past the door gives readable personal details at once.

In my view, the lasting problem is that this information does not change. Names and birth dates rarely change. Social Security numbers stay with a person for life and are used for credit, taxes and health care. Sex, race, service history and job type add detail that helps with impersonation and believable scam messages. Records of people who have died can also be used for fraud, because those identities are usually watched less closely.

In my view, the fixes are known. Keep personnel records separate from everyday file sharing, lock stored data with encryption and careful handling of the keys, and watch more closely for large copying or sending of data out. The October-to-July period points to slow detection as well as the first break-in. Worth flagging is the hopeful part: these are problems engineers know how to solve. They cost money and add some hassle, but they can shrink an attack from mass theft to a small contained incident. For a system this large, that difference matters to millions.