FBI and Pentagon Personnel Data Breached
The hacks exposed millions of federal records, including unencrypted Social Security numbers and psychiatric evaluations.
Updated on Sept. 26, 2026 in Cybersecurity

Live Poll
Do you trust federal agencies to secure your sensitive personal information from cyberattacks?
The FBI and the Pentagon have confirmed separate data breaches involving sensitive personnel information. Hackers from the group ShinyHunters accessed FBI servers, while the Defense Manpower Data Center suffered a massive exposure of employee records.
Why it matters
These breaches represent a significant failure in securing federal human resources data, potentially exposing millions of government employees to identity theft and foreign intelligence exploitation. The vulnerability of unencrypted records at the Pentagon highlights critical gaps in current federal cybersecurity hygiene.
The Pentagon breach involved the exfiltration of unencrypted records from the Defense Manpower Data Center, while the FBI hack resulted in the loss of 2 to 3 terabytes of internal server data. The stolen FBI files reportedly contain sensitive medical and psychiatric evaluations.
The players
FBI
The domestic intelligence and security service of the United States responsible for federal law enforcement.
Pentagon
The headquarters of the United States Department of Defense, managing military operations and personnel.
ShinyHunters
A hacking group known for exfiltrating and leaking large datasets from corporate and government entities.
The details
The Pentagon breach occurred because the Defense Manpower Data Center, a centralized repository for human resources data, stored millions of records without encryption. The FBI breach involved unauthorized access to internal agency servers by the hacking collective known as ShinyHunters, allowing them to download terabytes of sensitive personnel documentation.
Timeline
October 2025: Pentagon data breach began.
Fiscal year 2024: Defense Manpower Data Center housed 60 million records.
July 2026: Pentagon data breach discovered and fixed.
September 2026: FBI data breach details emerged.
The Tech Race
These incidents extend the precedent set by the 2015 Office of Personnel Management data breach regarding the mass exposure of government personnel files. They underscore the ongoing failure to secure legacy personnel databases against persistent state-sponsored and criminal cyber actors.
Millions of federal personnel may now be at risk of identity theft due to the exposure of Social Security numbers and medical records. Individuals impacted by the Pentagon breach should monitor for suspicious financial activity and official government notifications regarding credit monitoring services.
The takeaway
The exposure of unencrypted psychiatric and medical data creates long-term security risks that go beyond immediate identity theft concerns. Observers should track upcoming congressional oversight hearings regarding the Defense Manpower Data Center for updates on security policy changes.
Further reading
For more context on federal network vulnerabilities, see the Cybersecurity section.
Source note: This article includes information reported by The Daily Beast.
Live Poll
Do you trust federal agencies to secure your sensitive personal information from cyberattacks?









