There have been a number of recent incidents involving artificial intelligence agents attempting to gain unauthorized access to information stored on government agency websites, but data breaches continue due to traditional influence methods. A new incident involving the personal data of 3 million Pentagon employees gave unknown attackers months of access.
Image Credit: Unsplash, Julio Lopez
The leak became known thanks to a publication Reddit pagewhich provides the text of the notification affected personnel received following an internal investigation. The attack targeted the information infrastructure of the U.S. Department of Defense Personnel Data Center (DMDC), which contains personal data of active duty military personnel, civilian experts, and retired and deceased employees. The department said that between October 2025 and mid-July of this year, unknown unauthorized individuals accessed the department’s document resources. They have access to Pentagon personnel’s Social Security numbers, first and last names, dates of birth, gender and race information, and career data within the department. The email states that the data is stored in unencrypted form.
According to U.S. Department of Defense officials, the leak affected approximately 2.8 million living and retired employees and approximately 300,000 deceased employees. As of March this year, the Department of Defense provided employment to 1.3 million people, so the leaked content is not limited to active employees. The DCMC agency maintains data on military personnel and their family members and provides this data to various organizations upon request to process benefits and payments and provide medical services. The database may also contain information about U.S. military contractors. It is used to authenticate certain individuals when arranging access to U.S. military infrastructure.
Pentagon representatives said the department determined that the unidentified hackers did not have time to use the information received for malicious purposes. It’s unclear whether the hackers attempted to contact the Pentagon.
This is the second case in the past few months in which a U.S. law enforcement officer’s data has been stolen. In September, it was reported that the hacker group ShinyHunters had obtained the personal information of most FBI agents and job applicants. Representatives of the group promised not to publicly disseminate the information received, and one of the organizers of the attack was later arrested by the special unit. Similar events occurred in the more distant past. Back in 2015, the data of more than 22 million U.S. government employees fell into the hands of hackers, many of whom had access to classified information. It is believed that foreign intelligence services could use the data to try to recruit or pressure U.S. department employees to obtain necessary intelligence data.
If you find an error, select it with your mouse and press CTRL+ENTER.









