RackTop Systems
Threat Brief

The Pentagon personnel breach: nine months of file access, and a scope still written as “may”

Unauthorized users accessed unencrypted military personnel files on a Defense Manpower Data Center file-sharing system for nine months before the flaw was found. The notice to victims does not say how many people were affected.

RackTop Systems•September 28, 2026•7 min read

Key takeaways

  • According to public reporting from Military Times and CNN, the Defense Manpower Data Center (DMDC) discovered a vulnerability in a file-sharing system on July 16, 2026, and later analysis found that unauthorized users had accessed files containing unencrypted personal information between October 2025 and July 16, 2026.
  • Notification letters, including one sent on September 18, 2026, describe exposed Social Security numbers plus at least one other identifier, such as name, date of birth, contact information, sex, race, or military occupational specialty. Two people familiar with the incident told Military Times that approximately four million Defense Department personnel may be affected.
  • DMDC patched the vulnerability, restored the system, offered one year of credit monitoring and identity restoration through IDX, and said it had no indication the information had been misused. The letters describe access and do not give a count of people affected.
  • Storage-layer controls address both halves of the problem: behavioral detection of anomalous reads can shorten a nine-month window to a single session, and an immutable record of every file operation turns “may be affected” into a list of names.

In a notification letter sent on September 18, 2026 to a person whose records were in the affected files, the Defense Manpower Data Center explained how their information had been exposed. DMDC is the Pentagon organization that CNN reports held at least 60 million records as of fiscal 2024. According to public reporting from Military Times and CNN, DMDC discovered a vulnerability in a file-sharing system on July 16, 2026, and analysis after that discovery found that unauthorized users had accessed files on a server containing unencrypted personally identifiable information between October 2025 and July 16, 2026. The letters describe Social Security numbers exposed together with at least one other identifier, such as a name, date of birth, contact information, sex, race, or military personnel details including occupational specialty.

The letters do not say how many people were affected. Two people familiar with the incident told Military Times that approximately four million Defense Department personnel may be affected. DMDC patched the vulnerability and restored the system, is offering one year of credit monitoring and identity-restoration services through IDX, and said it had no indication that anyone’s information had been misused. The Pentagon has not said who accessed the files.

The access was found by finding the flaw

Read the timeline in order and one detail stands out. What DMDC discovered on July 16 was the vulnerability. The nine-month access window came afterward, from analysis of what the flaw had allowed. The reads themselves were not what surfaced the incident.

That sequence could describe nearly any file-sharing system in government or industry. A file service exists to answer requests, and once a flaw lets someone past the front door, the server fulfills their requests like any other. Unless something evaluates the pattern of those operations, nine months of unauthorized reads are indistinguishable from nine months of normal service.

The contents raise the stakes. Justin Sherman, CEO of Global Cyber Strategies, told CNN that in a foreign adversary’s hands this kind of data “could enable phishing, profiling, foreign intel approaches, and much more.” The 2015 theft of background-investigation files from the Office of Personnel Management showed how long personnel data keeps its value to an intelligence service.

What BrickStor SP would have seen in the first session

Had those files been served from RackTop BrickStor SP, every read would have been evaluated as it happened, and the first anomalous session is where the platform is built to intervene. Active Defense, the detection and response engine in BrickStor SP, inspects each file operation inline with the user identity, source IP address, file path, operation type, and timing attached. It profiles normal activity for each user, host, and dataset, and flags reads that fall outside that profile: an identity opening personnel files it has never touched, a source address with no history against the share, systematic copying, or an unusual cadence of access spread over weeks. When a session crosses that line, Active Defense terminates it in under a second, over SMB, NFS, S3, and Web Drive alike.

One caveat applies to any storage-layer control. If a flaw lets an intruder act through the file-sharing application’s own service account, the storage sees that account’s reads. Behavioral analysis still applies, since an application that normally serves individual files to individual users does not normally sweep an entire personnel dataset, but detection then rests on the application’s pattern rather than on an unfamiliar identity. RackTop’s analysis of the Cl0p Windchill implant covers that case in detail.

Attribute-based access control shrinks what a flaw can reach

Detection limits how long an intrusion runs. Least privilege limits how much it can touch before detection fires. BrickStor SP applies attribute-based access control (ABAC) to every SMB, NFS, S3, and Web Drive operation, deciding each request on who is asking, from where, on what device, at what time, and how the data itself is labeled. Files holding Social Security numbers can carry that label, and policy can restrict them to the roles, networks, and devices that actually process them. A flaw in a sharing front end then inherits a narrow slice of the server instead of every file on it.

The letters also say the files were unencrypted. BrickStor SP encrypts data at rest per dataset, using a FIPS 140-3 Level 1 validated cryptographic module in version 23.8 and later, and that closes a real exposure: stolen drives, copied disk images, and any access that goes around the file service. Its limits deserve the same precision. A user reading through the file service is served decrypted data, as every authorized reader is, so encryption by itself would not have stopped this access. The access decision and the behavioral check are the controls that act on a live request.

“May be affected” is an audit question

The number attached to this breach is conditional. Approximately four million people may be affected, according to Military Times’ sources, and the letters give no count. Figures phrased as “may” are what an organization can offer when it can establish that files were reachable but cannot yet list which ones were read. The cost of that uncertainty is real: everyone on the broad list must be notified and offered monitoring, and no one can say with confidence whether a given file was copied or merely exposed.

BrickStor SP keeps an immutable record of every file operation, with the user, their attributes, the resource, the action, the decision, and the policy rule that applied. With that record, scoping becomes a query: which files the unauthorized sessions opened, on which days, from which addresses, and which people those files describe. That answer supports a precise notification list and a direct statement about whether data left, which is the first thing every affected service member will want to know.

DMDC found the flaw, closed it, restored the system, and is notifying and protecting the people involved. The lesson for every agency and contractor running file-sharing infrastructure lies in the months before July 16, when unauthorized users had access and the storage serving the files was the system best positioned to notice. Behavioral detection in that layer turns nine months into one session, and an immutable record of every operation turns “may be affected” into a list.

Frequently asked questions

According to public reporting from Military Times and CNN, the Defense Manpower Data Center discovered a vulnerability in a file-sharing system on July 16, 2026. Analysis found that unauthorized users had accessed files containing unencrypted personal information, including Social Security numbers, between October 2025 and July 16, 2026. A notification letter was sent on September 18, 2026, and two people familiar with the incident told Military Times that approximately four million Defense Department personnel may be affected.
About nine months. The notification letters, as reported by Military Times and CNN, place unauthorized access between October 2025 and July 16, 2026, the day DMDC discovered the vulnerability in its file-sharing system. The access window was established by analysis after the vulnerability was found.
Not on its own. Encryption at rest protects against stolen drives, copied disk images, and access that bypasses the file service, and the exposed files were reported as unencrypted. But a user reading through the file service is served decrypted data, as any authorized reader is. Stopping that kind of access takes per-operation access control and behavioral detection of anomalous reads in the storage layer, with encryption underneath as a separate layer.
By evaluating every file operation, reads included, against a behavioral profile of each user, host, and dataset, and acting on sessions that depart from it. Unauthorized access shows up as identities opening files they have never touched, source addresses with no history against a share, systematic copying, or unusual access cadence over time. RackTop BrickStor SP does this inline with Active Defense and terminates anomalous sessions in under a second.Seven tests to evaluate Cyberstorage
With an immutable, per-operation audit of the storage holding the data: a record of which identity opened which file, when, from where, and under which policy decision. That record turns scoping into a query and supports a precise notification list, instead of notifying everyone whose data was reachable.

See what your file shares would have reported

A RackTop federal engineer can walk you through how BrickStor SP profiles reads, enforces ABAC on every operation, and keeps the immutable record that scopes an incident.

Pentagon DMDC Data Breach: 9 Months of File Access | RackTop