Kathmandu. There has been a major cyber attack on the database of the US Department of Defense (Pentagon). Unauthorized users accessed the Defense Manpower Data Center (DMDC) system between October 2025 and July 2026. The breach leaked the personal data of 2.76 million living and 2.94 million dead people. This included information such as names, social security numbers, dates of birth, contact details, and job details.
This data was not encrypted. This increased the risk. The Pentagon immediately fixed the error. So far, no evidence of data misuse has been found. Those affected have been offered a year of free credit monitoring. This incident raises serious questions about the safety and cyber preparedness of US military personnel.
The DMDC is the Pentagon’s primary personal records repository. It includes active-duty soldiers, reservists, civilian employees, contractors, retirees, veterans, and members of military families. The agency maintains more than 60 million records. This breach has leaked not only names and contacts, but also people’s job details.
This information is considered sensitive from a national security point of view. This is because it can provide insight into the military structure and roles. The number of unauthorized users is reported to be low. However, the long access clearly highlights the risks of the system. This error was discovered in July 2026 and immediately resolved.
According to officials, no abuses have been identified so far, but the risk is still there. – Agency












