The Pentagon DMDC Data Breach: What Was Exposed and What to Do Now

If you got a letter from the Defense Manpower Data Center last month, your Social Security number was sitting in an unencrypted file that outsiders could get to for the better part of a year.

DMDC is the Pentagon office that keeps military personnel records and the data behind every Common Access Card. On July 16, 2026 it found a security hole in one of its file-sharing systems and patched it that day. When it went back through the logs, it found that a small number of unauthorized users had been getting into a server full of unencrypted personal files since October 2025. The notification letters are dated September 18, and a Pentagon official has since told reporters the total is about 2.76 million living people and 294,000 who have died.

Who's affected by the DMDC data breach

The Defense Department hasn't put out a public notice, so most of what anyone knows comes from two places. One is the letter itself, which Military Times reviewed and two defense officials confirmed was real. The other is officials talking to reporters.

The official who gave the numbers to Federal News Network and TIME wouldn't say which groups those people fall into. News coverage describes current and former service members, and Stars and Stripes reports that civilian employees are in there as well. DMDC also keeps records on spouses and children, but nobody has said whether any of those were exposed.

So the simplest rule is this. If someone in your house got a letter, treat them as affected. The letters went out by mail, and if you've moved a few times since your address was last updated, yours may have gone somewhere else.

What was exposed

The letter says each person's Social Security number was exposed along with at least one other detail. That could be your name or date of birth, your contact information, your sex or race, or military information such as your occupational specialty. It varies from person to person. There's no mention of bank or card numbers.

The SSN is the obvious problem. The military details are the quieter one. Someone who knows your MOS and an old duty phone number can call claiming to be from finance or your unit, and it'll sound right.

The free monitoring, and what IDX's page gets wrong

DoD is paying for 12 months of credit monitoring and identity restoration through a company called IDX. A defense official gave TIME the enrollment page, response.idx.us/DMDC, and the phone number, 1-855-744-4556. You'll need the enrollment code printed in your letter. We haven't seen a deadline published.

It's worth signing up. But the advice on IDX's DMDC page is out of date in two places. It says a fraud alert lasts 90 days, when initial fraud alerts have lasted a year since 2018, according to the FTC. It also says a credit freeze is "an option best reserved for people who have experienced extreme identity theft."

We'd ignore that one. A freeze costs nothing and doesn't affect your credit score. More to the point, it's the only tool here that actually stops someone opening an account in your name. Monitoring tells you after it's happened.

There is one catch. IDX can't switch on its credit monitoring while your file is frozen, so enroll first, let the monitoring activate, and then freeze.

One more thing about the letter: it's been posted on Reddit, which makes it easy to fake. Type the IDX address in yourself instead of clicking a link someone emails or texts you.

DMDC data breach: what to do now

  1. Sign up for IDX using the code in your letter.
  2. Freeze your credit with Equifax, Experian and TransUnion. It takes a few minutes per bureau, and you can lift a freeze whenever you need to apply for something.
  3. If you're on active duty, add an active-duty alert to your file. Lenders then have to check with you before opening credit in your name. It lasts a year and can be renewed for the length of a deployment. Active-duty and National Guard members can also get free electronic credit monitoring from each bureau under an FTC rule, and that doesn't stop after 12 months the way the IDX offer does.
  4. Get an IRS Identity Protection PIN. It's a six-digit code that has to be on your tax return, so nobody else can file one using your SSN. Anyone can get one at IRS.gov, but the IRS only makes it available from mid-January to mid-November. Don't leave it until next year.
  5. If you have kids, freeze their credit too. The FTC says parents can do this for free for children under 16. Children's credit gets misused because nobody looks at it for years.
  6. If a parent or spouse who has died might be in the breach, tell the credit bureaus. About one in ten records involved belongs to someone who has died. A spouse or executor can send a copy of the death certificate to one bureau, and Equifax says that bureau will notify the other two. Experian's guidance explains who is allowed to make the request.
  7. If something does go wrong, start at IdentityTheft.gov. It walks you through a recovery plan and produces the report banks and bureaus ask for.

What we don't know yet

Quite a lot. DoD hasn't said who got in or whether they copied anything. It also hasn't explained why personnel files were sitting unencrypted on a file-sharing server, and it says it has seen no sign the data has been misused.

No hacking group has claimed this one. You may have seen ShinyHunters in the headlines the same week, but that was a separate breach at the FBI. We also haven't found a lawsuit over the DMDC breach yet. Suing a federal agency works differently from suing a company, so if one comes, it could take a while.

What a credit freeze doesn't cover

A freeze protects your SSN. It does nothing about your home address or the names of your family, and those are what make a scam call convincing. Both are easy to find on people-search sites, often for free. Military families tend to have long address histories on these sites because every PCS move adds another entry.

We see this constantly in our removal work. PeopleSearchNow, for example, shows past addresses and relatives on its free preview before it asks for any money. The data on these sites is often stale in ways that make removal harder. PeopleConnect, the company behind TruthFinder, Intelius and Instant Checkmate, verifies opt-outs by texting a phone number from its own records, and that number is often out of date.

Getting off these sites is a separate job from the freeze, and it isn't a one-time job either, because listings come back. Our guide to removing your personal information and the opt-out guides go through it site by site. Delist My Data is being built to do that work for you on a schedule. We're in pre-launch, and you can join the waitlist for founding-member access.

Sources

Find out which brokers are publishing your details.

No spam. One email when Delist My Data opens for your area.