Hackers steal records of 4.5 million U.S. military personnel in breach
Hackers accessed sensitive personal data of approximately 4.5 million U.S. military personnel through a compromised third-party vendor, exposing names, Social Security numbers, and service records. Tโฆ
The Department of Defense told millions of current and former U.S. service members on Tuesday that a cyberโattack had stolen their personal data during a breach that lasted several months. The notification, sent by the DoDโs Defense Information System Agency, says the breach exposed names, Social Security numbers, dates of birth and service records of roughly 4.5โฏmillion individuals.
The breach matters because military personnel records are a prized target for foreign intelligence services and criminal groups. In recent years, the Pentagon has faced a spate of cyber incidents, from ransomware attacks on its logistics network to the 2022 compromise of a contractorโs cloud environment. Those events have highlighted gaps in the defense departmentโs aging IT infrastructure and the growing sophistication of threat actors. The latest incident arrives as Congress pushes for stronger cybersecurity funding and tighter supplyโchain controls for defense contractors.
According to the agencyโs brief, attackers gained access through a compromised thirdโparty vendor that managed a legacy email system used by the DoD. Once inside, they moved laterally across networks, extracting data from personnel databases that were not fully segmented. The breach was discovered in early August, but the intrusion is believed to have begun in March. Defense officials, including Acting Secretary of Defense Kathleen Hicks, said the investigation is being led by the Cybersecurity and Infrastructure Security Agency and the FBI. The DoD has offered free identityโtheft protection services to those affected and is urging personnel to monitor credit reports for suspicious activity.
The department says it will complete a full forensic review by the end of the year and will harden its networks against similar attacks. Lawmakers have called for a congressional hearing to examine the incident and to assess whether current cyberโrisk management policies are sufficient. Meanwhile, service members are advised to change passwords, enable multiโfactor authentication on all accounts and watch for phishing attempts that may exploit the leaked information. The breach underscores the urgent need for modernizing defense IT and protecting the personal data of those who have served.
Read Full Story at TechCrunch โ

