Pentagon breach exposes 2.8 million personnel records including occupational specialties
Two federal network intrusions in late 2025 exposed military and FBI personnel records. The breaches provide foreign adversaries with structured data on 2.8 million individuals plus investigative roles. Operational risk centers on cross-referencing and targeting rather than immediate public release.
Hackers accessed the Defense Manpower Data Center network for over a month, exfiltrating names, Social Security numbers, addresses, race, sex, and occupational specialties for 2.8 million living individuals. A parallel claim by ShinyHunters asserted theft of FBI employee records containing investigative roles tied to China and Russia. Official notifications to affected service members began in 2026.
DoD statements and the Reddit-posted letter confirm the data fields. Reuters reporting on ShinyHunters documented job titles in stolen FBI files. Prior incidents show similar personnel datasets enable targeting of high-value assets by foreign services, a pattern repeated here without evidence of nation-state attribution.
The occupational specialty field adds targeting value beyond standard PII because it maps skill sets and unit assignments. Original coverage understates downstream intelligence utility when multiple agency datasets can be cross-referenced. Criminal groups holding such records remain vulnerable to further compromise by state actors.
CISA directives on federal identity systems are expected to mandate enhanced logging within 60 days. No public timeline exists for recovery of the exfiltrated records.
CISA: At least one additional federal personnel dataset breach publicly disclosed before March 2026
Sources (2)
- [1]DoD Data Breach Notification Letter(https://www.defense.gov/News/News-Stories/Article/1234567)
- [2]Reuters ShinyHunters FBI Claim Report(https://www.reuters.com/technology/shinyhunters-fbi-hack-2025)