in

Pentagon Admits Unencrypted Files Exposed Data on 3 Million People

The Pentagon finally confirmed what many feared: a Defense Manpower Data Center system left unencrypted files open to unauthorized users, exposing personal data tied to more than 3 million people. The mess includes Social Security numbers, names, birth dates and military job details. DMDC says it found the hole in mid‑July, patched it and began sending notification letters in September. That is the new and serious development everyone should be focused on.

How big is the DMDC breach?

This is not a run‑of‑the‑mill leak. The Department of Defense says roughly 2.76 million living people and about 294,000 deceased people had records exposed. The files covered standard personally identifiable information and, alarmingly, job and service details. Reporters say the exposure window ran from October of last year through July, and DMDC discovered the vulnerability on July 16. The agency says it has patched the system and is offering 12 months of credit monitoring through a contractor.

Who failed the people who serve?

Call it what it is: a breakdown in basic security for a database that holds tens of millions of personnel records. This is the same agency charged with guarding the identities of troops, veterans, civilians and family members — and yet unencrypted files sat exposed for months. Officials say there is no evidence so far that the data were abused, but “no evidence” is not the same as “no harm.” Two months passed between discovery and mass notification. That lag and the unanswered question of who accessed the files demand real oversight, not more soothing press releases.

National security risk — don’t downplay it

This breach is more than identity theft risk. When Social Security numbers are paired with military job specialties, locations and dates of birth, foreign intelligence services and hostile actors gain a useful map of personnel. That kind of data can be used to recruit, coerce or target service members and their families. If the Defense Department wants to protect national security, it must treat personnel data like classified information — not as an afterthought tucked into a legacy system.

What must happen next

Affected people should accept offered monitoring, freeze credit files, and stay vigilant. But the real fix is structural. Congress should hold hearings. The Pentagon must release a clear timeline, produce the forensic findings, and explain what long‑term protections will change. Twelve months of monitoring is damage control, not a plan. If we expect the Department of Defense to defend the nation, it must first stop leaving the identity of its people on a digital doormat. No more excuses — just real fixes and real accountability.

Written by Staff Reports

Leave a Reply

Your email address will not be published. Required fields are marked *

Harvard‑Harris Tie Means Republicans Can Win if They Mobilize

Harvard‑Harris Tie Means Republicans Can Win if They Mobilize

Judge Calvert Blocks DOJ Bid for Georgia's Unredacted Voter Rolls

Judge Calvert Blocks DOJ Bid for Georgia’s Unredacted Voter Rolls