Pentagon, FBI personnel-data breaches raise questions五角大楼和联邦调查局人员数据泄露事件引发质疑
The defense breach, which exposed about 3 million people, went undetected for months.

Kevin Carter/Getty Images
The defense breach, which exposed about 3 million people, went undetected for months.
A Pentagon breach that exposed sensitive personnel information for months is raising questions yet again about federal agencies' ability to detect unauthorized access to their records.
Information about roughly 3 million people was potentially exposed from October 2025 to July 16, 2026, by a breach of a file-sharing system at the Defense Manpower Data Center, which maintains personnel information used across the military and other government agencies.
“Three million people may be the headline, but months of unauthorized access to highly sensitive data going undetected is the real warning,” said Nitay Milner, co-founder and CEO of data security company ORION Security.
Nextgov/FCW obtained a copy of the letter, which was signed by DMDC Director Katie Griffin. The accessed files contained unencrypted personal information, including Social Security numbers and, depending on the individual, names, birth dates, contact information and military occupational specialties.
“Upon discovery of the security vulnerability, DMDC immediately initiated privacy and cybersecurity incident response actions in accordance with Office of the Management and Budget and [Defense] Department guidelines and policies,” Griffin wrote. “We are taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system.”
DMDC patched the flaw and restored the system, according to the letter, and affected individuals are being offered a year of credit monitoring and identity-restoration services.
Military Times first reported the incident late last month, citing the same notice. A defense official later told CNN that the breach affected 2.76 million living people and another 294,000 deceased individuals.
The disclosure comes as the FBI responds to a separate breach claimed by prolific cybercrime group ShinyHunters, which likely exposed sensitive records of personnel involved in intelligence-gathering roles.
No public evidence has linked the intrusions, though both cases involve information that could help attackers identify government personnel and tailor attempts to deceive them through fraud schemes. Such data can also identify employees whose work is of particular interest to foreign intelligence services.
The breach is hardly the first to expose weaknesses in federal systems in recent years. In December 2024, Treasury disclosed that Chinese state-sponsored hackers accessed unclassified documents through a compromised remote-support service. Separately, the federal judiciary acknowledged attacks on its electronic case management system in August 2025, and the Congressional Budget Office confirmed unauthorized access to its systems that November.
AI systems are widely expected to accelerate cyberattacks, helping hackers find security weaknesses and use stolen personal information to make their targeting more precise and convincing.
Milner said detecting unauthorized activity requires agencies to understand who is gathering sensitive information, whether they are permitted to enter a given system and whether their behavior makes sense.
That scrutiny can matter even when an intrusion doesn’t immediately disrupt a system or draw attention. In the case of DMDC, the department’s notification described access spanning roughly nine months before the vulnerability was discovered.
Jeff Wichman, senior director of breach preparedness and response at Semperis, said agencies must plan for intrusions even when they have experienced security teams and established protections.
“The FBI and Pentagon have amazing responders, but these breaches are still happening and eventually everyone is hit,” he said. “True resilience depends on having a fully pressure-tested incident response plan detailing exactly which teams are responsible for what across the entire breach cycle, from initial discovery and containment to legal and regulatory reporting.”
He also warned that new government AI services, including the America.gov chatbot , could create more ways for attackers to reach sensitive information if those tools connect to agency systems. “More government agencies will fall victim to compromise,” he said. “Every piece of leaked data creates a domino effect.”
NEXT STORY: China-linked hackers posed as former US officials, Anthropic employee to target AI experts
Kevin Carter/Getty Images
这次导致约300万人信息泄露的国防漏洞,数月来一直未被发现。
五角大楼的一次数据泄露事件导致敏感人事信息暴露数月之久,这再次引发了人们对联邦机构检测未经授权访问其记录能力的质疑。
2025 年 10 月至 2026 年 7 月 16 日期间,国防人力数据中心的文件共享系统遭到入侵,导致约 300 万人的信息可能泄露。该数据中心维护着军方和其他政府机构使用的人事信息。
“300万人可能只是新闻头条,但几个月来未经授权访问高度敏感数据却未被发现,这才是真正的警告,”数据安全公司ORION Security的联合创始人兼首席执行官Nitay Milner表示。
Nextgov/FCW 获得了这封信的副本,信由 DMDC 主任凯蒂·格里芬签署。被获取的文件包含未加密的个人信息,包括社会安全号码,以及根据个人情况而定的姓名、出生日期、联系方式和军事职业专长。
格里芬写道:“发现安全漏洞后,DMDC立即按照管理和预算办公室以及国防部的指导方针和政策启动了隐私和网络安全事件响应行动。我们正在采取适当措施,评估并加强DMDC系统的网络安全态势。”
信中称,DMDC 已修复该漏洞并恢复了系统,受影响的个人将获得一年的信用监控和身份恢复服务。
《军事时报》上月底率先报道了这起事件,并援引了同一份通知。一位国防部官员随后告诉CNN,此次数据泄露事件影响了276万在世人员和29.4万已故人员。
此次披露正值 FBI 对另一起由臭名昭著的网络犯罪组织 ShinyHunters 声称发生的泄露事件作出回应之际,该事件可能泄露了参与情报收集工作的人员的敏感记录。
虽然目前尚无公开证据表明这两起入侵事件之间存在关联,但两起案件都涉及可能帮助攻击者识别政府人员并制定针对性欺诈手段来欺骗他们的信息。此类数据还可以识别出那些工作对外国情报机构具有特殊意义的雇员。
近年来,联邦系统漏洞频发,此次事件并非首例。2024年12月,美国财政部披露,中国政府支持的黑客通过被入侵的远程支持服务获取了非机密文件。此外,联邦司法部门于2025年8月承认其电子案件管理系统遭到攻击,同年11月,国会预算办公室也证实其系统遭到未经授权的访问。
人们普遍预期人工智能系统将加速网络攻击,帮助黑客发现安全漏洞并利用窃取的个人信息,使他们的攻击目标更加精准、更具说服力。
米尔纳表示,要检测未经授权的活动,各机构需要了解谁在收集敏感信息,他们是否被允许进入特定系统,以及他们的行为是否合理。
即使入侵事件并未立即扰乱系统或引起关注,这种审查也至关重要。以DMDC为例,该部门的通知描述了漏洞被发现前大约九个月的访问情况。
Semperis 的高级安全漏洞防范和应对主管 Jeff Wichman 表示,即使拥有经验丰富的安全团队和已建立的保护措施,各机构也必须为入侵做好计划。
他说:“联邦调查局和五角大楼的应急响应人员非常出色,但这类安全漏洞仍然时有发生,最终每个人都会受到影响。真正的韧性取决于制定一套经过全面压力测试的事件响应计划,详细说明从最初的发现和遏制到法律和监管报告的整个漏洞周期中,各个团队的具体职责。”
他还警告说,包括America.gov聊天机器人在内的新型政府人工智能服务,如果与政府机构系统连接,可能会为攻击者提供更多获取敏感信息的途径。“更多政府机构将成为攻击目标,”他说。“每泄露一条数据都会产生连锁反应。”
下一篇报道:与中国有关联的黑客冒充美国前官员和人本主义组织员工,攻击人工智能专家