US War Department personnel breach exposes sensitive data
Note: AI technology was used to generate this article’s audio.
- A War Department database breach exposed sensitive personal data of over 3 million people.
- Unauthorized access went undetected from October 2025 to July 2026 before being patched.
- War officials reported no misuse to date and are offering free identity protection services.
- Hacking group ShinyHunters separately breached FBIJobs.gov, claiming access to employee data without leak intent.
A security breach of the War Department's central personnel database exposed sensitive information belonging to roughly 3 million active, civilian, and former military personnel, a US War official told ABC News.
The breach involved the unauthorized exposure of Social Security numbers and specific job history details.
According to the War official speaking to ABC News, the breach compromised records belonging to 2.76 million living individuals, alongside an additional 294,000 deceased persons.
Breach spanned October 2025 to July 2026
The incident occurred within an information system operated by the Defense Manpower Data Center (DMDC), which serves as a primary repository housing over 60 million records across active-duty troops, reserves, civilian personnel, contractors, retirees, veterans, and military dependents.
"A Defense Manpower Data Center (DMDC) information system experienced unauthorized access of personally identifiable information by a small number of unauthorized users between October 2025 and July 2026. Upon discovery, DMDC immediately remediated the vulnerability," the War official told ABC News.
War Department officials emphasized to ABC News that investigators have found no evidence thus far that any of the exposed information has been misused.
The agency is offering credit monitoring and identity protection resources to affected individuals.
The breach was initially reported last week by Military Times.
FBI addresses separate breach
The disclosures regarding the War Department follow an internal notification sent Friday by the FBI to its workforce detailing a security breach affecting its unclassified job application portal, FBIJobs.gov, ABC News reported.
A threat actor claimed it obtained records including names, home addresses, contact information, Social Security numbers, birth dates, and emergency contacts of bureau personnel.
Sources told ABC News that the FBI is proceeding under the assumption that all employee personal information was compromised.
However, in a statement provided Monday to The New York Times and 404 Media, the hacker group shinyhunters stated it would not leak or publish the data.
"Since the very beginning of this event we have unequivocally and assiduously emphasised this is NOT extortion, this is NOT ransom, this is NOT financially motivated," the group claimed in its statement. "This was all a marketing campaign to protect our business and actively combat disinformation. If we made this statement normally then this much attention to our words and intentions would’ve never been this widespread."
ABC News noted it has not independently verified the group's claims.
Impacted FBI employees have begun receiving formal notifications and were advised by bureau guidance to maintain situational awareness, avoid answering suspicious communications, and notify local authorities if media members trespass on personal property, ABC News reported.



