Pentagon data breach of military personnel raises national security concerns五角大楼泄露军事人员数据事件引发国家安全担忧
A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national security experts.

Kevin Lamarque/Reuters
A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national security experts.
“Unauthorized users” gained access to a vulnerable computer server belonging to the Defense Manpower Data Center (DMDC) beginning last October, but it wasn’t until nine months later, in July, that the Pentagon discovered and remediated the issue, according to a letter the center sent to victims of the breach reviewed by CNN.
The DMDC maintained at least 60 million records as of fiscal 2024, according to its website. It’s unclear how many have been impacted, but Military Times reported that four million Department of Defense personnel could be affected by the breach.
The Pentagon currently “does not have any indications of misuse” of the breached data, according to the letter. But the breached data is a potential goldmine for foreign intelligence services looking to track US military personnel, or cybercriminals looking to extort them (were they to acquire the data), according to experts.
One piece of data accessed by the intruders in some cases was the “occupational specialty” of military service members, according to the letter, which is dated this month. That, when combined with other datasets using identifiers like Social Security numbers, could give foreign adversaries a clearer read on who does what for the US military in various parts of the world.
It’s unclear who was behind the breach. A Pentagon spokesperson did not immediately respond to CNN’s questions, including who the culprit was.
US military leaders have repeatedly warned their troops that their phones and online accounts could be targets during the war with Iran. US Central Command, which spans the Middle East and beyond, told lawmakers in the spring that it had “received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil US personnel in theater.”
A bad actor could pair the information taken from DMDC with other commercial datasets to “learn about or even target [defense personnel] based on their earnings, debts, marriages, spending habits, browsing activities, and worse,” said Justin Sherman, CEO of advisory firm Global Cyber Strategies and the author of an upcoming book on the data broker industry.
The DMDC is “the one, central access point” for information on Department of Defense entitlements, benefits and “medical readiness” for military personnel, veterans and their families, according to the center’s website.
“The services and access to data we provide support so many vital government entities,” the DMDC website says, “including the legislative branch, human services, national defense, labor, healthcare, finance, veterans affairs, research, and more.”
The stolen data wasn’t encrypted, according to the letter. Encrypting sensitive data is a standard security practice.
“We are taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system,” the letter says while offering victims a year of credit monitoring services.
“On its own, having personal data on potentially millions of service members exposed is dangerous as the US wages war on Iran and is in competition with multiple other governments,” Sherman told CNN. “If a foreign adversary was to get this kind of data trove, it could enable phishing, profiling, foreign intel approaches, and much more.”
凯文·拉马克/路透社
五角大楼庞大的人力资源系统发生数据泄露,导致现役和退役军人的社会保障号码和其他个人信息泄露,引发了国家安全专家对反间谍活动的担忧。
据 CNN 审阅的一封国防人力数据中心 (DMDC) 致受害者的信函显示,自去年 10 月起,“未经授权的用户”访问了该数据中心的一台存在漏洞的计算机服务器,但直到九个月后的 7 月,五角大楼才发现并修复了该问题。
据其官网显示,截至2024财年,国防部军事数据中心(DMDC)至少保存了6000万条记录。目前尚不清楚有多少人受到影响,但《军事时报》报道称,此次数据泄露事件可能影响到400万国防部人员。
五角大楼在信中表示,目前“没有任何迹象表明泄露的数据被滥用”。但专家指出,对于试图追踪美国军方人员的外国情报机构,以及试图敲诈勒索他们的网络犯罪分子(如果他们获取了这些数据),这些泄露的数据都可能成为一座金矿。
根据本月发出的这封信函,入侵者在某些情况下获取的数据之一是军人的“职业专长”。如果将这一信息与其他使用社会保障号码等标识符的数据集结合起来,外国敌对势力就能更清楚地了解美国军方在世界各地不同岗位的具体人员构成。
目前尚不清楚是谁发动了此次入侵。五角大楼发言人尚未回复CNN的提问,包括肇事者是谁。
美国军方领导人多次警告部队,在与伊朗的战争期间,他们的手机和网络账户可能成为攻击目标。美国中央司令部(其管辖范围涵盖中东及其他地区)在今年春季向国会议员表示,他们“收到了多份威胁报告,涉及敌方利用商业位置数据来锁定或监视战区内的美国人员”。
全球网络战略咨询公司首席执行官、即将出版的关于数据经纪行业的书籍作者贾斯汀·谢尔曼表示,不法分子可以将从DMDC获取的信息与其他商业数据集结合起来,“根据[国防人员]的收入、债务、婚姻、消费习惯、浏览活动等信息来了解甚至锁定他们”。
据该中心网站介绍,DMDC 是军人、退伍军人及其家属获取国防部权利、福利和“医疗准备”信息的“唯一中央入口”。
“我们提供的服务和数据访问权限为许多重要的政府机构提供支持,”DMDC 网站上写道,“包括立法部门、人力服务部门、国防部门、劳工部门、医疗保健部门、金融部门、退伍军人事务部门、研究部门等等。”
信中指出,被盗数据并未加密。对敏感数据进行加密是标准的安全措施。
信中表示:“我们正在采取适当措施来评估和加强DMDC系统的网络安全状况”,同时向受害者提供一年的信用监控服务。
谢尔曼告诉CNN:“仅就美国对伊朗发动战争并与多个其他国家政府竞争而言,数百万军人的个人数据泄露本身就十分危险。如果外国敌对势力获得这类数据,就可能进行网络钓鱼、用户画像分析、外国情报活动等等。”