• Massive Pentagon hack sees records of 2.7 million US military per

    From TechnologyDaily@1337:1/100 to All on Thursday, October 01, 2026 17:15:22
    Massive Pentagon hack sees records of 2.7 million US military personnel
    leaked during months-long data breach names, military service records and Social Security numbers all revealed

    Date:
    Thu, 01 Oct 2026 16:05:00 +0000

    Description:
    A bug in a file-sharing service exposed sensitive employee data and allowed malicious actors to extract information on millions of people.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Breach exposed PII of three million current and former DoD-affiliated individuals Attackers accessed unencrypted data for months via vulnerable file-sharing system Stolen records included SSNs, military roles, and sensitive personnel details Three million people, both living and deceased, who either work and used to work for a division of the US Department of War (DoW, also known as the DoD), have had their personally identifiable information (PII) stolen in a cyberattack that went on undetected for months.

    The Department of War runs a component called the Defense Manpower Data
    Center (DMDC). It is the DoDs personnel-data agency that collects and maintains personnel and workforce data. It manages large databases with information about military personnel, civilian employees, contractors, and other individuals connected to the US defense community. The DMDC also provides data and analytical services to support military operations. Latest Videos From TechRadar Watch full video here: Breach confirmed Roughly two weeks ago, a person shared a photograph on Reddit, showing a data breach notification letter they received in their mail. In the letter, the DMDC explained what happened, and offered complementary identity theft monitoring services:

    On July 16, 2026, a security vulnerability in a DMDC file sharing system was discovered, which allowed unauthorized users to access files, the letter reads. DMDC immediately updated the file sharing system to patch the vulnerability and the system was restored. You may like Thousands of US military beneficiaries have data breached following TRICARE cyberattack Massive data breach sees 220 million traveler records exposed nine years of airline info leaked including passenger and passport details Gyazo breach exposes 23.62 million user records and 490 million image records PII and metadata exposed in huge attack

    A subsequent investigation determined that someone used the flaw to access servers containing unencrypted PII in October 2025. Between then, and July 2026, they were extracting all sorts of information, including Social
    Security numbers (SSN), full names, dates of birth, contact information, sex, race, and military personnel information such as occupational specialty.

    Speaking to CNN , an official of the Department of War confirmed the breach, saying it affects 2.76 million living individuals, and 294,000 deceased ones. According to the DMDC website, the organization handles more than 60 million records. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    At press time, we were still missing key details. We dont know which file sharing system was targeted, or what the flaw is. Just a few days ago, secure file-sharing service Kiteworks warned its customers to shut down their
    servers for nine hours, in anticipation of an incoming cyberattack. Links to Kiteworks? Kiteworks is a large secure file-sharing service that works with government agencies, including US federal, state, and local governments. On its website, the company explicitly says that defense contractors use its platform to protect CUI and FCI that they exchange with the DoD, although it does not confirm working directly with the agency. Kiteworks also markets dedicated government solutions and says its platform is FedRAMP authorized
    for federal use.

    Cybercriminals such as Cl0p are known for targeting this type of service. A few years ago, major breaches at MOVEit and GoAnywhere MFT resulted in data leaks in thousands of organizations. The damage is in the millions. What to read next Massive supply-chain attack sees terabytes of data leaked online US healthcare software giant Unlimited Technology Systems admits hackers may
    have stolen sensitive data of 3.8 million people FBI launches investigation after 153 million drivers licenses apparently leaked on Russian cybercrime forum

    Further in the letter, the DoW says there are so far no indications of the files being misused, although it is safe to assume the files will either be sold on the black market, or used for highly tailored phishing emails. The attackers could use the information to trick victims into sharing login credentials, ultimately accessing even more sensitive DoW servers and causing even further damage.

    CNN says the occupational specialty information could be extremely valuable
    to foreign nation-state threat actors, because it can be combined with Social Security numbers to get a clearer read on who does what for the US military
    in various parts of the world.

    The DMDC said it patched the flaw as soon as it discovered it, so its safe to assume this wasnt a zero-day. Besides taking appropriate actions to assess
    and enhance the cybersecurity posture of the DMDC system, the agency also
    said it was now offering 12 months of credit monitoring services through IDX. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/massive-pentagon-hack-sees-records-of-2 -7-million-us-military-personnel-leaked-during-months-long-data-breach-names-m ilitary-service-records-and-social-security-numbers-all-revealed


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)