LiMP VPN
← All news

Pentagon Breach Exposes SSNs of 3 Million People

Pentagon Breach Exposes SSNs of 3 Million People

In short: According to ABC News, hackers breached the U.S. Department of Defense Civilian Personnel Data System (DCPDS) and stole personal data belonging to more than 3 million people — 2.76 million living individuals and 294,000 deceased ones. The unauthorized access ran from October 2025 through July 2026, going undetected for nearly nine months. The stolen data includes Social Security numbers, job roles, and other records on active-duty service members, reservists, civilian employees, contractors, veterans, and their families.

What happened

DCPDS is one of the Pentagon's core personnel-data repositories, holding records on active-duty and reserve service members, civilian staff, contractors, retirees, veterans, and military families. According to sources familiar with the investigation cited by ABC News, attackers gained unauthorized access to the system as early as October 2025 and retained it until July 2026 — meaning the intrusion went unnoticed by routine monitoring for nearly nine months.

No official statement detailing the attack vector or the group responsible had been issued at the time of publication. The breach itself and its scale have been confirmed through dedicated reporting and corroborated by multiple outlets.

What data was exposed

The exposed data includes Social Security numbers (SSNs) — one of the most sensitive identifiers in the U.S., used to open bank accounts, apply for credit, and access government services — along with job titles, service status, and other personnel attributes. The breach affects 2.76 million living individuals and 294,000 deceased people whose records remained in the system. Spouse information is also mentioned separately, a typical detail in personnel databases of this scale that widens the pool of affected people well beyond the department's own employees.

Why this matters beyond the military community

An SSN leak isn't a one-time incident — it's a long-tail risk. Unlike a password, a Social Security number can't simply be "changed," so stolen data stays usable for fraud for years. Attackers build phishing and vishing scenarios around an SSN and accompanying personnel details: a call or email "from HR" that cites a victim's exact job title looks far more convincing than a generic scam blast. We've covered a similar social-engineering tactic in our piece on social engineering and device-code phishing.

The nine months of undetected access is itself telling: it means the stolen data could have already circulated through underground channels long before the breach was officially disclosed, leaving victims aware of the risk only after it had already materialized.

What to do if you might be affected

  • Watch for official notifications from the U.S. Department of Defense. Breaches of this kind typically come with notification letters offering instructions and free credit-monitoring enrollment.
  • Freeze your credit with the three major U.S. bureaus (Equifax, Experian, TransUnion) if you have reason to believe your SSN was exposed — a freeze blocks new accounts from being opened in your name until you lift it.
  • Be wary of calls or messages where the caller knows your job title, service status, or other "internal" details — that's not proof of legitimacy, it's a sign they have access to a leaked database.
  • Use unique passwords and two-factor authentication for banking and government services — an SSN alone doesn't grant account access if a strong second factor is enabled.
  • Encrypt your network traffic where it matters. LiMP VPN hides your IP address and protects data in transit from interception on public Wi-Fi and other untrusted networks — a complementary layer of protection, not a replacement for the steps above: a VPN cannot erase data from a database that's already been stolen.

Sources