Pentagon tells more than 2 million military members their records were stolen

The Pentagon is informing more than 2 million current and former military members that their personnel records, which hold sensitive personal information, were stolen in a monthslong compromise of one of its networks. The breach is the second in recent months to expose sensitive government information.
According to one notification letter posted to Reddit, the stolen records included Social Security numbers, names, addresses, sex, race, and occupational specialty. The article says that last category could be particularly valuable to foreign adversaries, because it could help their intelligence agencies identify high-value military personnel.
Starting last October, hackers gained access to a system operated by the Defense Manpower Data Center, which collates Department of Defense personnel records. The Pentagon says the breach compromised the records of 2.8 million living individuals. The article gives this figure alongside the "more than 2 million" notification figure and does not reconcile the two.
The article sets the incident beside an earlier one. Last month, the ransomware group ShinyHunters claimed it hacked into FBI systems and stole records of thousands of the agency's current or former employees. Reuters reported that the job titles in those records included ones related to investigating China or Russia. ShinyHunters said it has no plans to release the information, but the article notes that the promises of a criminal organization that has hacked and extorted hundreds of organizations mean very little. It adds that the group's cyber defenses are likely no match against nation-state intelligence hackers. An FBI official this week called on group members to turn themselves in.
Key facts
- The Pentagon is informing more than 2 million current and former military members that their personnel records were stolen; it says the records of 2.8 million living individuals were compromised.
- Hackers got into a Defense Manpower Data Center system starting last October, and the compromise lasted months.
- One notification letter posted to Reddit lists Social Security numbers, names, addresses, sex, race, and occupational specialty as the stolen fields.
- It is the second recent breach of US government personnel data: last month ShinyHunters claimed it stole records of thousands of current or former FBI employees.
- ShinyHunters says it will not release the FBI data, but the article says the word of a group that has extorted hundreds of organizations means very little.
Why it matters
Personnel records of this kind are a rich target. The article says occupational specialty could help foreign intelligence agencies pick out high-value military personnel, and it describes the Pentagon and FBI incidents as two cases in recent months where sensitive government personnel records were exposed, records that criminal groups or foreign adversaries could use. The scale is large: more than 2 million people are being notified, and the Pentagon puts the compromised records at 2.8 million living individuals.
Who it affects
Current and former military members whose records sat in the Defense Manpower Data Center system, which collates Department of Defense personnel records. Separately, thousands of current or former FBI employees are named in the data ShinyHunters says it stole; Reuters reported that the job titles in those records included ones related to investigating China or Russia.
How to use it
This is a news report, not a product or tool. The practical point for readers is that the Pentagon is notifying affected people, and one such notification letter, which was posted to Reddit, is the article's source for the list of stolen data fields.
How solid is it
The core facts come from the Pentagon's own notifications and statement: more than 2 million people informed, and 2.8 million living individuals compromised. The list of stolen fields rests on a single notification letter posted to Reddit. The FBI breach is a claim by ShinyHunters, and the source does not say whether the FBI confirmed it. The Reuters detail about job titles is reported second-hand. The two Pentagon figures are not reconciled in the article.
Risks and caveats
The source does not say who the hackers in the Pentagon breach were, and it does not tie that breach to ShinyHunters or to any foreign state. It also does not say how the intruders got in, or whether the stolen data has been sold, published or used. The article's assessments of the risk to personnel are hedged: occupational specialty "could" be valuable to foreign adversaries, and ShinyHunters' defenses are "likely" no match for nation-state hackers. The year of the October start is not given.