The Pentagon's breach letter is dated 64 days after the flaw was found, and says accessed, not stolen
The Defense Manpower Data Center says a flaw in a file-sharing system was discovered on 16 July and that unauthorised users had accessed unencrypted personnel files since October 2025. Its letter is dated 18 September and does not name the system, the flaw, the actor or the count.
By Parminder Kumar Sharma · · 18 min read

64 days from discovery to the date on the letter
The Defense Manpower Data Center (DMDC), the Pentagon's personnel records unit, says in its notice letter that "a security vulnerability in a DMDC file sharing system was discovered" on 16 July 2026. The letter is dated 18 September 2026. That is 64 days (our arithmetic: 15 days left in July, 31 in August, 18 in September). The same letter says "a small number of unauthorized users" had been accessing files on a server "between October 2025 and the date of discovery". That is 258 to 288 days of access before the flaw was found, depending on which day in October it began, and 322 to 352 days from the first possible access to the date on the letter. Both ranges are ours; the letter gives no day.
That fact does not establish much of what the headlines around it suggest. It does not show that anyone broke a rule: the two sets of rules we could read ask for notification "as expeditiously as practicable and without unreasonable delay" and set no day count for the letter to individuals. The clock that does count days, seven for telling Congress, starts when an agency determines that a major incident has occurred, and that date is not public. It does not show the data was stolen: the letter says users "accessed files", and "stole" is the headlines' verb. It does not name the system, the flaw, the actor or the number of people. The count of 2.76 million living and 294,000 deceased individuals comes from an unnamed Pentagon official talking to reporters, not from the letter.
Nor is this a story about the UK. No source we read mentions the United Kingdom, UK-based US personnel, the Ministry of Defence or UK suppliers. What carries over to a UK team is the shape of the gap: what was reached, when it was found, when people were told, and what the notice leaves out.
The record, in dates
Dates on the public record. The letter's wording is as quoted by the outlets named; report dates are the outlets' own.
| Date | What the record says | Basis |
|---|---|---|
| October 2025 (day not stated) | Unauthorised users begin accessing files on a server: access ran "between October 2025 and the date of discovery". | Notice letter, quoted by SecurityWeek and Security Affairs |
| 16 July 2026 | A "security vulnerability in a DMDC file sharing system was discovered". DMDC says it updated the system to patch it and the system was restored. | Notice letter, quoted by SecurityWeek and Security Affairs |
| 18 September 2026 | Date on the letter. Military Times says its copy was sent that day to an individual whose data was in the affected files. | SecurityWeek; Military Times |
| 24 September 2026 | Military Times reports the letter. Two defense officials confirm it is authentic. | Military Times |
| 28 to 29 September 2026 | A Defense Department official gives CNN, ABC News, Federal News Network and TIME the counts: 2.76 million living and 294,000 deceased individuals. | CNN, ABC News, Federal News Network, TIME |
| 1 October 2026 | BleepingComputer reports that DMDC is notifying service members. Enrolment for the credit monitoring offer closes on 19 August 2027, as reported from the letter. | BleepingComputer; Security Affairs |
The intervals, all ours: access before discovery 258 to 288 days; discovery to the letter date 64 days (nine weeks and one day); the letter date to the first press report 6 days; discovery to the first official count we found, 74 days; letter date to the enrol-by date 335 days. When letters were posted or received is not stated, but Military Times had one in hand by 24 September, so some had arrived within six days of the date on them.
One breach, five ways of stating how many
The count is where the coverage drifts furthest from the source. The letter gives none: SecurityWeek says it "does not say how many people are affected". The figures all trace to an unnamed Pentagon official speaking to reporters, plus one earlier estimate from unnamed sources.
How the count is worded, who said it and what it does not establish. Sums and shares are our arithmetic.
| Wording and where | What it counts | What it does not establish |
|---|---|---|
| "2.76 million living individuals" and "294,000 deceased individuals": an unnamed Pentagon official to CNN, ABC News, TIME and Federal News Network, 28 to 29 September | Individuals, living and deceased counted separately | Which groups they belong to. No published document gives the figures. |
| "More than 3 million": Federal News Network and BleepingComputer's headline | 2,760,000 + 294,000 = 3,054,000 (our sum) | Anything beyond the sum. BleepingComputer's own URL still reads "nearly 3 million". |
| "Nearly 3 million": ABC News headline, BleepingComputer URL | The living figure, 2.76 million, rounded up | The deceased. Federal News Network's "nearly 2.8 million" living is the same figure rounded. |
| "Approximately four million": two unnamed people to Military Times, 24 September | An estimate before the official count | Any confirmation. It is 946,000 above the official total (derived). A NewsNation headline says the letter gives up to four million; we saw the headline but could not read the article, and SecurityWeek says the letter gives no count while Military Times attributes the figure to two people familiar. |
| "Records": Tom's Hardware, and BleepingComputer's "personnel records of over 3 million people" | Records, which the official's wording does not use | How many records each person has. The official counted individuals. |
For scale, DMDC's own site says it holds "60 Million+ DoD Person Records" on fiscal 2024 data. If the 3,054,000 sit inside that figure, they are at most 5.1 per cent of it; the sources do not say whether they do. Counting accounts or records as if they were people is a familiar slip: our briefing on Times Car found a company counting accounts, not people.
Who is in the count is the question the count cannot answer. DMDC describes its records as military, civilian, contractor, family member, retiree and veteran. Federal News Network reports that the official declined to say whether those affected belong to a particular group. CNN calls "living individuals" a category that "potentially includes" current and former defence personnel or their dependents, which is CNN's reading and not the Department's wording. Whether family members and veterans are among the 2.76 million is not stated.
Accessed, not stolen: the words the notice chose
The friendly-name fallacy is the habit of mistaking a comforting label for a control or a fact. This record has labels in both directions: some soften, and some, in the headlines, claim more than the notice does. Each phrase below is accurate as far as it goes. The point is what it leaves out.
Phrases in the notice, the Pentagon's statements and the coverage, and what the record shows about each.
| Phrase, and who used it | What the record shows |
|---|---|
| "Hackers stole" (BleepingComputer headline and text) | The notice says unauthorised users "accessed files". Copying or downloading is not stated, and nor is who the users were. OMB treats unauthorised access to the data of 100,000 or more people as needing a major incident determination, so access is serious on its own terms, but "stole" is a stronger claim than the notice makes. |
| "The Pentagon's human resources management system" (BleepingComputer); "vast HR system" (CNN) | The letter says "a DMDC file sharing system" and "a server"; the official says "a DMDC information system". The HR label is the outlets'. No product, vendor or version is named. |
| "Immediately updated" and "immediately remediated" (letter; official to ABC News) | Immediately after discovery, which came 258 to 288 days after access began. The date of the patch is not given. |
| "A small number of unauthorized users" (letter and official) | No number, origin or motive. "Users" does not say outsiders. The official declined to say whether the breach was intentional. |
| "Does not have any indications of misuse" (letter) | A statement about misuse, not about access. TechCrunch reports the Pentagon did not say how it reached that conclusion, or answer whether it had heard from the intruders. |
| "Credit monitoring" (the offer) | Monitoring detects changes to a credit file; it does not stop new credit being opened. IDX's page calls a freeze "best reserved for people who have experienced extreme identity theft". The FTC says "Anyone can freeze their credit report, for any reason". |
| "DoW" (letter), "Department of Defense" (DMDC's pages), "U.S. Department of War" (war.gov) | One department, three styles. We say "the Pentagon" and quote each source's own wording. |
What is stated, and what is not
Questions a reader would ask, checked against the letter as quoted, the Pentagon statements to reporters and the other sources read. Attribution is to the outlet quoting.
| Question | Stated on the record | Not stated |
|---|---|---|
| Which system? | "A DMDC file sharing system" and "a server" (letter); "a DMDC information system" (official). | Product, vendor, version, CVE. No source ties it to any vendor advisory; treat any such link as speculation. |
| How did they get in? | A "security vulnerability" "which allowed unauthorized users to access files" (letter). | The kind of flaw, whether it was reached remotely, whether credentials were involved, how long it had existed or whether it was publicly known. |
| When? | Access "between October 2025 and the date of discovery"; discovered 16 July 2026; letter dated 18 September 2026. | The first day of access, how the flaw was found, when each person was identified, when letters were posted. |
| What was taken? | Files on a server holding "unencrypted PII" were accessed. | Whether files were copied, how many, or which. |
| What data? | A Social Security number plus at least one of: name, date of birth, contact information, sex, race, military personnel information such as occupational specialty. It varies by person. | Which contact fields; whether financial, health or dependants' data were in the files; whether every file had the same fields. |
| How many? | 2.76 million living and 294,000 deceased individuals, from an unnamed official. | Any document with the figure; the split by service members, civilians, contractors, family members and veterans. |
| Who? | "A small number of unauthorized users." SecurityWeek says no known group appears to have taken credit. | Identity, origin, motive. The official declined to say who accessed the data. No source links this to the FBI incident that BleepingComputer mentions. |
| Is it for sale or published? | "No indications of misuse". | How that was checked, and whether the data has been offered anywhere. |
| What help? | 12 months of credit monitoring through IDX; enrolment to 19 August 2027 as reported. IDX's page says the monitoring is "for adults". | Cover for minors or for the families of the 294,000 deceased; any help with a changed Social Security number. |
| Who was told? | The letter cites OMB and Department guidelines. | Whether Congress, the inspector general or CISA were notified, or when. We found no congressional or inspector general statement. |
Is 64 days late? The rules count differently
Four clocks are in play: three that apply to the Pentagon and one UK comparison. None of the three can be checked from the public record, because each either sets no day count or starts at a decision the public record does not date.
The clocks, from OMB's M-17-12 (3 January 2017) and M-25-04 (15 January 2025), DoD Manual 5400.11 Volume 2 (6 May 2021), 44 U.S.C. 3554 and the ICO's breach guide.
| Clock | What the rule says and when it starts | Public for DMDC |
|---|---|---|
| Telling affected individuals (OMB M-17-12; DoD Manual 5400.11 Vol. 2) | "As expeditiously as practicable and without unreasonable delay". No fixed number of days. Delay is allowed on the say of the Attorney General, an intelligence agency head or the Secretary of Homeland Security if notice would disrupt law enforcement, endanger national security or hamper remediation. | The letter date. No statement that a delay was requested. |
| Telling Congress and the inspector general (44 U.S.C. 3554; M-25-04) | Within 7 days of the date the agency has a reasonable basis to conclude a major incident occurred. OMB requires a major incident determination for unauthorised access to the PII of 100,000 or more people. | Not stated whether a determination was made, or when. |
| Telling CISA and OMB (M-25-04) | Within 1 hour of determining a major incident. | Nothing. |
| UK comparison: telling the ICO (UK GDPR) | Within 72 hours of becoming aware, where feasible; individuals without undue delay if the risk is high. This does not apply to DMDC. | Not applicable. |
The seven-day clock starts at a determination, not at discovery. OMB's own footnote says an agency "will take some time to determine" whether an incident is major. So 64 days is a measure of when the letter was dated, not proof that a rule was missed, and not proof it was kept. M-25-04 also does not apply to national security systems, and the notice does not say whether this server was one. It is the most recent OMB memorandum we could read; OMB issues them annually, so a later one may apply.
OMB and the Department do set what a notice should contain: what happened with the dates of the breach and of its discovery, the types of data, whether it was encrypted, what people should do, what the agency is doing and whom to contact. As quoted, the letter covers most of that. We have not seen the whole letter, so we do not score it.
Four measurements from three cases, from this briefing and two earlier ones. They are not the same clock: two measure time to detect and two measure time to tell.
| Case | What the days measure | Days |
|---|---|---|
| DMDC, Pentagon | First access to discovery, October 2025 to 16 July 2026 | 258 to 288 |
| DMDC, Pentagon | Discovery to the date on the letter | 64 |
| [France's tax authority](https://www.pk-sharma.com/briefing/french-tax-authority-learned-of-theft-49-days-later) | First extraction to first knowledge, 24 June to 12 August 2026 | 49 |
| [Australia's Medicare portal](https://www.pk-sharma.com/briefing/openai-agent-medicare-portal-84-day-disclosure) | Incident to notification of the government, 18 June to 10 September 2026 | 84 |
Unencrypted, and what that does not tell us
The letter says the server held "unencrypted PII", and Federal News Network reports the official declined to say why. Encryption at rest protects against some routes, such as a stolen disk or a copied backup, and not against others, such as an intruder who reaches the application that serves the files, which decrypts them for its users. The notice does not say how the files were reached, so it does not say whether encryption would have changed the outcome. That is our reasoning about the technique, not a finding.
What the data is good for is also opinion at this stage. The files included a Social Security number and, for some people, an occupational specialty. Justin Sherman of Global Cyber Strategies told CNN a foreign adversary with such data could mount "phishing, profiling, foreign intel approaches, and much more". That is one analyst's view of what is possible, relayed by CNN. No source reports any such use.
The UK angle: nothing named, and what carries over
Access is not copy, and the ICO says so. The ICO's guide gives a worked example close to this one: an organisation finds files holding personal data were accessed but does not know how the attacker got in or whether the data was copied. The ICO's answer is to notify within 72 hours of becoming aware, say what is not yet known, and send more as it is found.
The UK clock is a day count. Under UK GDPR a notifiable breach goes to the ICO within 72 hours of awareness, where feasible, and high-risk breaches go to individuals without undue delay. As an illustration only, a UK controller aware on 16 July would have reached the 72-hour mark on 19 July. Earlier briefings cover the 72 hour clock and the others that run to a regulator, and a gap of 49 days before an authority learned of a theft.
Suppliers and staff. A UK firm that supports US defence programmes, hosts US personnel or processes their records for a US customer may hold data on people in this count. The notice does not say. The question is for the customer, in writing.
What to do, in the order worth doing it
Take this with you
Actions, in order
- List every file-sharing and file-transfer service that holds personal data, including web file shares, SFTP and managed transfer products. For each, record the owner, the product and version, what personal data it holds and how long files stay.
- Check which of them hold unencrypted personal data, and write down what the encryption you do have would stop and what it would not, for example a stolen disk against an intruder using the application.
- Find out how far back the access logs on those services go, and whether they record who opened and who downloaded each file. Access that ran for 258 days or more would not show its start in a 90-day log.
- Make access versus copy a question your logs can answer: keep download and outbound transfer records for those servers, so the first notice you write can say which.
- Pre-write the ICO notification and the individual notice. Include the dates of the incident and of discovery, the data types, whether it was encrypted, what people should do and a named contact, so missing facts do not hold up a notice.
- Set an internal deadline for deciding whether to tell individuals, and record the reason each time it slips.
- Ask suppliers who run file services for you how fast they would tell you of unauthorised access, and put the number in the contract. UK GDPR Article 33(2) already requires a processor to tell the controller without undue delay.
- If you hold or process US defence personnel data, ask the customer in writing whether your staff or records are in the count. Warn anyone who received a letter that the enrolment link will be imitated: enrol only through the web address printed in the letter.
- For anyone with a letter: enrol by 19 August 2027 using the letter's own address, and consider a credit freeze, which the FTC says anyone can place at no cost and which lasts until lifted, rather than relying on monitoring alone.
Method and interest
The notice letter is the primary source and we did not read it directly. Its wording comes from SecurityWeek and Security Affairs, which quote it at length, and from Military Times, Stars and Stripes and CNN, which quote and describe it; where wording appears in one outlet only, it is attributed. The counts rest on an unnamed official speaking to reporters; no document gives them. The Pentagon has an obvious interest in how the incident is described, and the notice is the account of the body that suffered the breach. It is accurate as far as we can check on what it states, and it says little about how the flaw was used. IDX is a contractor to the Department, per Military Times, and has a commercial interest in enrolment; its page is a service page, not an investigation. We have no commercial interest in the story and name no individual or group.
Things that could be overtaken in an hour, as of mid-morning BST on 1 October 2026: the first page of the war.gov release list, which runs from 18 September, carries no release on the incident; DMDC's home page carries no notice; the first page of California's attorney general breach list, which covers entries reported from 1 to 29 September, has no DMDC entry, though we could not search Maine's or other states' lists by name; and we found no congressional or inspector general statement. We read the OMB memoranda as published; we could not read the 2007 DoD privacy regulation, whose site blocked our request, so we make no claim about its older notification rule.
The question that exposes the gap
If an unauthorised user opened files on one of your file servers today, which log would tell you by Monday whether they copied them, how far back does that log go, and who would be told first?
Key facts
Sources
- PrimaryEnrolment page for the DMDC offer, read in full: 12 months of credit monitoring described as for adults, restoration help tied to enrolment, and the page's own advice on credit freezesIDX (contractor to the Department, named by a Pentagon official to TIME)accessed 2026-10-01
- PrimaryDMDC overview page and home page, read in full in a browser: 60 Million+ person records on fiscal 2024 data, office locations, no mention of the UK and no notice of the incidentDefense Manpower Data Centeraccessed 2026-10-01
- PrimaryFirst page of the release list on 1 October 2026, running from 18 September: used to confirm no release on the incident was listedU.S. Department of Waraccessed 2026-10-01
- PrimaryMemorandum M-25-04 of 15 January 2025, read for the major incident definition, the 100,000-person threshold, the 7-day and 1-hour clocks and the national security systems exclusionOffice of Management and Budgetaccessed 2026-10-01
- PrimaryMemorandum M-17-12 of 3 January 2017, read for the timeliness and contents of a notification to individuals and the lawful grounds for delayOffice of Management and Budgetaccessed 2026-10-01
- PrimaryDoD Manual 5400.11 Volume 2, breach preparedness and response plan, effective 6 May 2021: the Department's own wording on timeliness, delay and the 7-day report to CongressU.S. Department of Defense (copy hosted by the Department of the Navy CIO)accessed 2026-10-01
- PrimaryText of 44 U.S.C. 3554: the statutory 7-day notice to Congress for a major incidentLegal Information Institute, Cornell Law Schoolaccessed 2026-10-01
- PrimaryPersonal data breaches: a guide, read for the 72-hour rule, the duty to tell individuals without undue delay and the worked example of files accessed but not known to be copiedInformation Commissioner's Officeaccessed 2026-10-01
- PrimaryCredit freezes and fraud alerts: used for who can place a free freeze and how long it lastsFederal Trade Commissionaccessed 2026-10-01
- PrimaryFirst page of the breach list, entries reported 1 to 29 September 2026: used to confirm no DMDC entryCalifornia Attorney Generalaccessed 2026-10-01
- Reported byFirst report of the notice letter, 24 September 2026: dates, data types, the credit monitoring offer, authenticity confirmed by two defense officials, and the unnamed estimate of about four millionMilitary Timesaccessed 2026-10-01
- Reported by29 September 2026: quotes the letter's wording on discovery, access, unencrypted data and misuse, and states the letter gives no countSecurityWeekaccessed 2026-10-01
- Reported byQuotes the letter at length, including the data types and the enrolment deadline of 19 August 2027Security Affairsaccessed 2026-10-01
- Reported by29 September 2026: the letter was uploaded to the r/AirForce forum and matches the Military Times reportStars and Stripesaccessed 2026-10-01
- Reported by25 September 2026, updated 28 September: the Pentagon's 2.76 million and 294,000 figures, no answer on who was behind it, and an analyst's view of what the data enablesCNNaccessed 2026-10-01
- Reported by28 September 2026: the defense official's statement and the 2.76 million and 294,000 figuresABC Newsaccessed 2026-10-01
- Reported by28 September 2026: the official's account, the questions the official declined to answer, and the more-than-3-million wordingFederal News Networkaccessed 2026-10-01
- Reported by29 September 2026: confirmation of the counts by a Pentagon official and the IDX enrolment addressTIMEaccessed 2026-10-01
- Reported by30 September 2026: the Pentagon did not say how it concluded there was no misuse or answer whether it had heard from the intrudersTechCrunchaccessed 2026-10-01
- Reported byUsed only for its wording of the count as records rather than individualsTom's Hardwareaccessed 2026-10-01
- Reported by1 October 2026, read in a browser because its feed blocks curl: the pointer for this briefing; headline wording, the stole verb and the enrolment deadlineBleepingComputeraccessed 2026-10-01


