Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Two Federal Agencies Were Hacked in a Month, and the Data They Lost Is a Windfall

A second major network breach spills the personnel records of thousands of federal employees, exposing names, numbers, and secrets.

By mitch·5 min read
A cracked digital map glows red as binary code rains down, symbolizing a breach of federal agency secrets.

The Pentagon is notifying more than 2 million current and former military members that their personnel records were stolen in a months-long network compromise. The Defense Manpower Data Center, which collates Department of Defense personnel records, was breached starting last October, according to the Pentagon.

Notification letters posted to Reddit say records stolen include Social Security numbers, names, addresses, sex, race, and occupational specialty. The Pentagon says the breach compromised the records of 2.8 million living individuals.

The Defense Manpower Data Center Breach

The Defense Manpower Data Center serves as the central repository for Department of Defense personnel records. Its role is to collect and store data on military personnel across the armed forces.

Advertisement

The compromise began last October. The full timeline of the breach remains unclear, but the notification letters now being sent out confirm that the data theft lasted for months.

The scale of the breach is enormous. More than 2 million service members and veterans could receive notification letters in the coming weeks. The Pentagon says the breach compromised records of 2.8 million living individuals, a figure that exceeds the number of affected service members.

The stolen data includes highly sensitive information. Social Security numbers, names, addresses, sex, race, and occupational specialty are all part of what was taken. That combination of identifiers puts affected individuals at risk of identity theft and financial fraud.

The letters note that the records stolen included Social Security numbers, names, addresses, sex, race, and occupational specialty.

What the Notification Letters Reveal

Reddit users have posted images of the notification letters they received. The letters describe the scope of the data exposed.

The letters also confirm that the breach compromised the records of 2.8 million living individuals.

The Second Major Network Breach in Recent Months

This hack is the second major network breach in recent months to expose sensitive US government personnel records. Last month, ransomware group ShinyHunters claimed it hacked FBI systems and stole records of thousands of current or former employees.

ShinyHunters is a well-known ransomware group that has targeted multiple organizations. Its modus operandi involves infiltrating networks, stealing data, and threatening to release it unless a ransom is paid.

The FBI breach involved records of thousands of current or former employees. Job titles in those records included positions related to investigating China or Russia, according to Reuters.

The FBI has responded publicly to the threat. An FBI official called on group members to turn themselves in. ShinyHunters has said it has no plans to release the information.

Comparing the Two Breaches

Breach Affected Organization Number of Records Stolen Data Exposed
Defense Manpower Data Center Department of Defense 2.8 million living individuals Social Security numbers, names, addresses, sex, race, occupational specialty
ShinyHunters FBI Thousands of employees Job titles related to China and Russia investigations

Both breaches share a common thread: they involve sensitive government personnel records. Both involve large numbers of affected individuals. And both highlight the vulnerability of federal agency networks.

The timing of the two breaches is notable. They occurred within a single month. That proximity raises questions about whether there is a broader pattern of cyberattacks targeting government systems.

The Risk to Individuals

The stolen data includes Social Security numbers, which are unique identifiers used for everything from tax filings to banking. Names, addresses, and other personal details can be combined with the Social Security numbers to create complete profiles of affected individuals.

Identity theft is a serious risk. Criminals who obtain this data can open accounts in victims’ names, file fraudulent tax returns, and access bank accounts. The damage can take years to repair.

Monitoring credit reports and alerting credit agencies is a prudent step.

The Broader Context of Cybersecurity

Cybersecurity has become a defining challenge for governments around the world. Nation-state hackers, criminal groups, and insider threats all target government networks.

Federal agencies hold vast amounts of sensitive data. That data includes personnel records, health information, and financial data. Protecting it requires constant vigilance.

The defense sector is a particular target. Military networks contain information that adversaries want. The Defense Manpower Data Center is a central repository for personnel data, making it a valuable target for attackers.

What Comes Next

The Pentagon is now in the process of notifying affected individuals. That process will take weeks, possibly months.

Affected individuals should watch for notification letters. They should read the letters carefully and follow the advice provided.

The two breaches raise questions about the state of cybersecurity at federal agencies. The Defense Manpower Data Center breach shows that even large, well-funded organizations can be compromised.

The stolen data is a reminder of the stakes. The Defense Manpower Data Center breach is a significant incident. It affects millions of individuals and exposes sensitive personal information. The fact that it happened at all is deeply troubling.

The FBI breach adds to the concern. Together, the two incidents show a pattern of cyberattacks targeting government personnel records.

The Pentagon and the FBI need to improve their cybersecurity posture. The breaches demonstrate that current protections are insufficient. The stolen data is a reminder of the stakes.

Affected individuals should take the warnings seriously. They should monitor their credit and stay alert for signs of fraud. The notification letters are the beginning of a long process of recovery.

Where the paper stands

The paper backs neither side here but stands firm against the very thing that caused this: an agency collecting vast stores of personal data without restraint, which makes breaches like this possible at all. The Defense Manpower Data Center was never designed to hold the records of millions of military members, and its collapse shows what happens when government treats citizens’ lives as mere data.

The paper’s position is simple: power that gathers in one place gets abused. The Defense Manpower Data Center was not built to handle the volume of data it collected, and the result was predictable. A smaller, more distributed system might have failed too, but it would have failed in a way that affected fewer people and exposed less at once. Instead, one breach compromised records belonging to 2.8 million living individuals.

The reader should watch for the next notification letter, because another breach is likely coming. The pattern is clear: federal agencies hold vast stores of personal data, and attackers keep finding ways in. The paper will continue to warn against agencies writing their own authority and collecting more power, whatever party holds it.

Source material: “Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data,” Ars Technica.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.