In late September 2026, two U.S. federal agencies landed in data-breach headlines within days of each other. The first hit the Defense Department’s Defense Manpower Data Center (DMDC), where unauthorized users got in through a vulnerable file-sharing system. The second involves the FBI, where the extortion group ShinyHunters claims it stole employee and applicant data. Ars Technica reported both incidents together.
How bad it is depends on which one you mean. The DMDC incident is confirmed by the Defense Department’s own notification letter, and the vulnerability is patched. The letter says unauthorized users had access to Social Security numbers and other personal data on about 2.76 million living and 294,000 deceased people. The FBI incident began as a claim by a criminal group. The FBI says it’s investigating, and reporters matched a leaked sample to real personnel records, but the full scope hasn’t been confirmed. Sources are linked throughout, including Federal News Network, SAN, CBS News, and TechCrunch.
What Happened
The DMDC breach (confirmed by DoD letter, now patched)
For context, DMDC as a whole maintains records on more than 60 million troops and veterans, current and former civilian employees, contractors, and military family members, per Federal News Network. That is the size of the system, not the size of this incident, which affected about 3 million people. Personnel data like this is harder to recover from than a typical password leak because much of it is permanent. You can rotate a password. You can’t rotate your Social Security number or your service history.
According to Federal News Network, SAN, and Ars Technica, the timeline runs like this:
| Date (approx.) | Event | Status |
|---|---|---|
| October 2025 | Unauthorized users begin accessing files through a vulnerable DMDC file-sharing system | Per DoD letter |
| July 16, 2026 | The vulnerability is discovered and patched | Per DoD letter |
| September 18, 2026 | DoD notification letter dated | Reported by multiple outlets |
| Late September 2026 | Press coverage appears (reports dated roughly Sept. 24–29) | Reported |
That’s roughly nine months of access before the hole was closed, and the notification letter is dated September 18, a little over two months after the fix. Officials haven’t publicly explained that interval. Officials haven’t said whether data was downloaded or only viewed, per SAN, and the letter says there’s no indication anyone’s information has been misused.
The letter, as reported by SAN, lists these categories. Not every field applies to every person; the specific data accessed varied by individual:
- Social Security numbers
- Names
- Dates of birth
- Contact information
- Sex
- Race
- Military occupational specialty (MOS)
In our assessment, an SSN combined with a name and date of birth is the kind of data identity thieves look for, and an MOS paired with contact details could make service-themed phishing more convincing. Neither risk has been reported as happening in this case.
The FBI incident (FBI investigating, scope unconfirmed)
In September 2026, the group ShinyHunters claimed it had stolen FBI employee and applicant data, per Ars Technica. The group says it took 2 to 3 terabytes of data and got in through an Oracle PeopleSoft server, per CBS News and TechCrunch.
Treat the details carefully. The FBI said it “is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” according to TechCrunch. Reuters and 404 Media reported that a leaked sample matched real FBI or Justice Department personnel records, though neither confirmed the records came from FBI systems, CBS News reported. What remains unconfirmed is the intrusion path and the full scope. Extortion groups have every reason to inflate claims, so treat the terabyte figure and the “nearly all employees” framing as claims until the Bureau says more. There are no confirmed victim numbers.
Why these two incidents are reported together
They hit the news within days of each other. That’s the link. The intrusions themselves are a different story. The DMDC access reportedly began in late 2025, while the FBI claim surfaced in September 2026. None of the coverage we reviewed links them to a shared attacker or method. They fit a pattern of federal exposure, and that’s all the evidence supports.
How It Stacks Up
Confirmed vs. claimed
| DMDC / Defense Dept. | FBI | |
|---|---|---|
| Status | Confirmed by DoD letter; vulnerability patched | ShinyHunters claim; FBI investigating; leaked sample matched real records per Reuters and 404 Media; scope unconfirmed |
| Entry point | Vulnerable file-sharing system | Claimed: Oracle PeopleSoft server (unconfirmed) |
| Dwell time | ~9 months (Oct 2025 – Jul 16, 2026) | Unknown |
| Data categories | SSNs, names, dates of birth, contact info, sex, race, MOS | Employee and applicant data; leaked samples included names, home addresses, and phone numbers |
| Victim count | 2.76M living + 294,000 deceased (outlets round differently, see below) | Not quantified |
| Source | Federal News Network, Ars Technica, SAN, SC World, TechRadar | Ars Technica, CBS News, TechCrunch |
The DMDC victim count doesn’t match across outlets
This is where a lot of write-ups get sloppy. Each source counts something slightly different:
| Figure | What it counts | Source |
|---|---|---|
| ~2.8 million | Living individuals | Ars Technica |
| 2.7 million | “US military personnel” (headline figure) | TechRadar |
| 2.76 million living + 294,000 deceased (≈3.05 million total) | Living and deceased records combined | Federal News Network, TIME |
The explanation is simple. The letter’s figures, as reported by Federal News Network and TIME, are 2.76 million living and 294,000 deceased people. Some outlets count only the living. Others add the deceased records. Some round 2.76 million up to 2.8 million, and others round it down to 2.7 million. If you’re writing a risk assessment or briefing leadership, cite the letter’s figures and name your source.
The Reaction
Reaction has been thin so far. On X, most posts just share the story, including Ars Technica’s own post.
Coverage itself splits by tone, according to SAN’s media comparison. Left-leaning outlets called the data a counterintelligence “potential goldmine.” Center outlets separated unauthorized access from confirmed misuse and noted the uncertain totals. Right-leaning outlets stressed government failure and possible theft.
The center reading fits the evidence best. Nine months of unnoticed access to a personnel-records system is a serious failure. But the Pentagon hasn’t said whether data was taken, and the FBI incident is still under investigation. Lumping both into one confirmed catastrophe goes beyond what’s known.
Our Take
Verdict: Act now if you’re potentially affected. If you run IT anywhere, adopt the lesson rather than just piloting it.
There’s no product to adopt or reject here. The useful question for an IT shop is whether you’d catch a nine-month intrusion through a file-sharing tool on your own network. Be honest about the answer. Fixing it costs mostly staff time: an inventory, a patch cadence, and log review. That’s far cheaper than a breach-notification campaign.
Our read on the evidence:
- DMDC is the better-documented incident. The DoD’s own letter confirms it, the data is sensitive and permanent, and the dwell time is the headline lesson.
- The FBI claim is a “watch” item. The FBI says it is investigating claims of unauthorized activity affecting FBIjobs.gov, and reporters matched a leaked sample to real records, but don’t repeat ShinyHunters’ framing as fact — the full scope and intrusion path remain unconfirmed. A verified sample isn’t a verified scope. Wait for the Bureau to say more.
- The victim-count mess is itself a finding. When agencies don’t publish a clear notice, the press fills the gap with rounded numbers that don’t match.
If you might be affected (military and DoD-connected readers)
Assume your SSN, address, and MOS are now in criminal hands, and act on that basis:
- Freeze your credit with all three major U.S. credit bureaus. A freeze is free and stops new credit lines from being opened in your name.
- Watch for targeted phishing. Messages that mention your MOS, unit, or service history are now easier to fake. Treat unexpected “DoD benefits” or “records update” emails as hostile until you’ve verified them through a channel you already know.
- Lock down your accounts. Use a password manager and add a hardware security key, such as a YubiKey, to email and financial accounts. A stolen SSN is far more dangerous when attackers can also reset your email password.
- Watch for an official notice. Use only official channels you can verify yourself. Don’t trust links in unsolicited messages that claim to be breach notices.
If you run IT: find your forgotten file-sharing services
This section is general defensive guidance, not remediation specific to the federal incidents. The DMDC entry point was reportedly a file-sharing system. These are classic “set up years ago, never touched since” services. Start by listing what’s listening on your network and when it was last patched.
Linux (Ubuntu 24.04 / Debian 12)
List listening services so you can spot SMB, FTP, WebDAV, or web-based file transfer apps you forgot about:
# -t TCP, -l listening only, -n numeric ports, -p show owning process (needs sudo)
sudo ss -tlnp
Expected output (trimmed):
State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
LISTEN 0 50 0.0.0.0:445 0.0.0.0:* users:((“smbd”,pid=1123,fd=31))
LISTEN 0 4096 0.0.0.0:22 0.0.0.0:* users:((“sshd”,pid=842,fd=3))
LISTEN 0 511 0.0.0.0:8443 0.0.0.0:* users:((“java”,pid=2210,fd=12))
Anything bound to 0.0.0.0 on a file-sharing port like 445, 21, or an unfamiliar high port deserves a second look. 0.0.0.0 means the service listens on every IPv4 interface. It doesn’t prove the port is reachable from the internet, so check your firewall and edge rules too. Next, check for pending security updates:
# Refresh package lists, then show what's waiting to be upgraded
sudo apt update
apt list --upgradable
If the list includes the file-sharing package, that’s your priority. An empty list doesn’t prove a service is safe, only that apt has nothing newer. One catch: commercial file-transfer apps installed outside apt won’t show up here. You’ll need to check those against the vendor’s advisories by hand.
Windows Server (2019 / 2022 / 2025)
List SMB shares and their paths in an elevated PowerShell session:
# Shows every SMB share, including admin shares ending in $
Get-SmbShare | Select-Object Name, Path, Description
Expected output (trimmed):
Name Path Description
—- —- ———–
ADMIN$ C:\Windows Remote Admin
C$ C:\ Default share
Finance D:\Shares\Finance
Scans D:\Scans
Then check when the server last received updates:
# Five most recently installed hotfixes, newest first
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5 HotFixID, InstalledOn
If the newest InstalledOn date is months old, look closer. Get-HotFix reads the Win32_QuickFixEngineering class, which doesn’t return every update type, so confirm in Settings > Windows Update > Update history or your patch-management tool.
The broader lessons for security teams
- Patch file-sharing systems on a short cycle. CISA’s Known Exploited Vulnerabilities catalog sets short remediation deadlines for federal agencies; we recommend treating internet-facing file-transfer tools with similar urgency.
- Measure dwell time as well as entry. Forward file-share access logs to a central system and alert on bulk downloads. Nine months of undetected access is the lesson here, whatever was or wasn’t taken.
- Minimize the data you keep. Ask why a file-sharing system had access to SSNs and race data at all. Data you don’t store can’t leak.
- Rehearse disclosure. The two-month gap between the patch and the notification letter, plus the conflicting numbers, shows what happens without one clear, official notice. Know your notification duties. Have a single official statement ready before you need it.
For homelab admins, the same rules apply on a smaller scale. That old Samba share on your NAS, or the file server on a Raspberry Pi in the closet, is your version of DMDC’s forgotten system.
Wrapping Up
The Pentagon’s DMDC breach is confirmed by the department’s own letter and patched. Unauthorized users had access to SSNs, contact details, demographic data, and MOS for about 2.76 million living and 294,000 deceased people. The FBI incident began as a ShinyHunters claim. The FBI is investigating and reporters matched a leaked sample to real records, but the full scope remains unconfirmed. Keep the two separate when you talk about them, and cite every number with its source.
The record count is bad, but the scarier detail is the nine months nobody noticed. Most organizations should assume they have the same blind spot until they’ve proven otherwise.
| Step | Action | Applies To |
|---|---|---|
| 1 | Freeze credit and enable hardware-key MFA | Potentially affected individuals |
| 2 | Treat MOS- or service-themed emails as phishing until verified | Military / DoD-connected readers |
| 3 | Inventory listening file-sharing services (ss -tlnp, Get-SmbShare) | Linux and Windows admins |
| 4 | Check patch recency (apt list --upgradable, Get-HotFix) | Linux and Windows admins |
| 5 | Centralize file-share logs and alert on bulk transfers | Security teams |
| 6 | Report the FBI incident as under investigation, with the scope still unconfirmed | Anyone writing or briefing on this |