Hacks of Two US Federal Agencies in a Month Expose Millions of Sensitive Records
The Pentagon is notifying more than 2 million current and former military members that their personnel data was stolen in a long-running network breach, marking the second major US federal agency hack exposed in recent months.

The US Department of Defense is notifying more than 2 million current and former military members that sensitive personal data was stolen during a monthslong compromise of one of its networks. According to a notification letter posted to Reddit, the stolen records included Social Security numbers, names, addresses, sex, race, and occupational specialty. That last category could be especially valuable to foreign intelligence services, since it may help identify high-value military personnel.
The breach began last October, when hackers gained access to a system run by the Defense Manpower Data Center, which compiles personnel records for the entire Department of Defense. The Pentagon says the intrusion compromised records belonging to 2.8 million living individuals.
Second breach in recent months
This marks the second time in recent months that a major network breach has exposed sensitive US government personnel data that criminal groups or foreign adversaries could exploit. Last month, the ransomware group ShinyHunters claimed it had broken into FBI systems and stolen records on thousands of current and former agency employees. According to Reuters, those records included job titles tied to investigations of China and Russia.
ShinyHunters has said it does not plan to release the stolen data, but such assurances carry little weight coming from a criminal group that has already hacked and extorted hundreds of organizations. Experts also note that such groups' cybersecurity defenses are unlikely to hold up against nation-state intelligence hackers who might seek the same data. An FBI official this week urged members of the group to turn themselves in.


