A vulnerability in US Department of Defense contractors and personnel systems has allowed intruders to obtain the personal data of millions of active-duty and former military personnel. The perpetrators went undetected in the system since at least October of last year, with the Pentagon uncovering the issue nine months later, in July.
The breach involves the Defense Manpower Data Center, which stores records for service members, veterans, and their family members. The database contains at least 60 million records, and preliminary estimates suggest the number of affected individuals could reach around 4 million.
Unauthorized users accessed one of the center's vulnerable servers, gaining access to information on service members, including their military occupational specialties. The Pentagon reports that no evidence of the stolen data being misused has been detected so far.
At the same time, cybersecurity experts are raising alarms over serious risks. If cross-referenced with commercial sources, the compromised data could allow foreign intelligence agencies to ascertain service members' income, debts, marital status, and spending habits. This information could subsequently be exploited for targeted phishing campaigns or recruitment attempts.
Of particular concern is that the stolen information was unencrypted—a fundamental standard for protecting sensitive data. Who stands behind the attack remains unknown.
The Pentagon has offered affected individuals one year of free credit monitoring services and announced measures to bolster the system's cyber defenses.
This incident highlights just how vulnerable even the most highly protected military data infrastructure can be. Remaining unnoticed in the system for nine months is a serious red flag for the US cybersecurity apparatus.
Notably, the stolen data was unencrypted, representing a violation of basic information security rules. Such an oversight enables adversary intelligence services to leverage the collected data for targeted pressure or the expansion of espionage networks.
In the coming period, the central question will be whether the Pentagon can identify the true perpetrators of the attack and prevent similar leaks in the future.

