The Defense Manpower Data Center is notifying service members that attackers used a file-sharing vulnerability to reach personnel data between October 2025 and July 2026. Letters described by BleepingComputer list Social Security numbers, names, dates of birth, contact information, sex, race, and military personnel information.

Pentagon officials told Federal News Network the incident covers more than 3 million people, including nearly 2.8 million living and 294,000 deceased. Twelve months of IDX credit monitoring is on offer, with enrollment through August 19, 2027. Those two outlets are the sources I used.

Notifications in fall 2026 are late for anyone who already had a tax-return fight this year. Credit monitoring is a year. Military identity data is fuel for tax fraud, benefit theft, and targeted social engineering. If I got a DMDC letter, I would freeze credit, watch tax transcripts, and enroll in the offered monitoring before the 2027 cutoff. I would ignore random Pentagon-breach-help DMs.