Security News Pentagon data breach of military personnel raises national security concerns

Security News
1 Reply 152 Views

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national security experts.

The Pentagon has confirmed that the breach affects 2.76 million “living individuals,” a category that potentially includes current and former defense personnel or their dependents, and 294,000 “deceased individuals,” a Defense Department official told CNN on Monday, three days after this story was published.

“Unauthorized users” gained access to a vulnerable computer server belonging to the Defense Manpower Data Center (DMDC) beginning last October, but it wasn’t until nine months later, in July, that the Pentagon discovered and remediated the issue, according to a letter the center sent to victims of the breach reviewed by CNN.

The DMDC maintained at least 60 million records as of fiscal 2024, according to its website.
The Pentagon currently “does not have any indications of misuse” of the breached data, according to the letter. But the breached data is a potential goldmine for foreign intelligence services looking to track US military personnel, or cybercriminals looking to extort them (were they to acquire the data), according to experts.

One piece of data accessed by the intruders in some cases was the “occupational specialty” of military service members, according to the letter, which is dated this month. That, when combined with other datasets using identifiers like Social Security numbers, could give foreign adversaries a clearer read on who does what for the US military in various parts of the world.

It’s unclear who was behind the breach. A Pentagon spokesperson did not immediately respond to CNN’s question on who the culprit was.

US military leaders have repeatedly warned their troops that their phones and online accounts could be targets during the war with Iran. US Central Command, which spans the Middle East and beyond, told lawmakers in the spring that it had “received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil US personnel in theater.”
A bad actor could pair the information taken from DMDC with other commercial datasets to “learn about or even target [defense personnel] based on their earnings, debts, marriages, spending habits, browsing activities, and worse,” said Justin Sherman, CEO of advisory firm Global Cyber Strategies and the author of an upcoming book on the data broker industry.

The DMDC is “the one, central access point” for information on Department of Defense entitlements, benefits and “medical readiness” for military personnel, veterans and their families, according to the center’s website.

“The services and access to data we provide support so many vital government entities,” the DMDC website says, “including the legislative branch, human services, national defense, labor, healthcare, finance, veterans affairs, research, and more.”

The stolen data wasn’t encrypted, according to the letter. Encrypting sensitive data is a standard security practice.
“We are taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system,” the letter says while offering victims a year of credit monitoring services.

“On its own, having personal data on potentially millions of service members exposed is dangerous as the US wages war on Iran and is in competition with multiple other governments,” Sherman told CNN. “If a foreign adversary was to get this kind of data trove, it could enable phishing, profiling, foreign intel approaches, and much more.”
 
Hi Brownie2019, the national-security concern is credible, although the confirmed facts are narrower than the headline: unauthorized users accessed sensitive DMDC records for roughly nine months, while the attacker, the full extent of copying, and any subsequent misuse remain unknown.

CNN’s updated report says the Pentagon confirmed 2.76 million affected living individuals and 294,000 deceased individuals. That is about 3.05 million people, but not necessarily 3.05 million service members; the population may also include former personnel and dependants. Occupational-specialty information was reportedly exposed only in some cases.

“No indications of misuse” should not be read as “no harm occurred.” Ordinary identity fraud may eventually appear in credit records, but intelligence collection, profiling and carefully targeted phishing can remain invisible. Combining an SSN and occupational specialty with commercially available location, financial or relationship data is a plausible counterintelligence risk. It is not evidence that a foreign government has actually done so in this incident.

The unencrypted data makes the potential exposure worse, but encryption is not the whole story. Encryption at rest may offer little protection if an intruder reaches a running system that is already permitted to read the records. The prolonged access window and apparent failure to detect unauthorized access promptly are at least as concerning.

Sensible steps for notified people​


  1. Verify the notice independently. Visit an official .mil or .gov site or use a previously known contact number. Do not trust links or telephone numbers in unexpected follow-up messages; criminals will almost certainly imitate this notification.
  2. Accept the offered monitoring, but consider freezing credit at all three bureaus. Monitoring mainly reports activity after it happens, while a freeze makes opening new credit harder. The FTC explains the differences and how to place either protection.
  3. Review existing credit reports and important financial or benefit accounts. Investigate unfamiliar applications, address changes or account-recovery activity rather than waiting for the monitoring service to flag something.
  4. Treat unusually well-informed messages with suspicion. Knowledge of a person’s SSN fragment, service history, speciality or dependant details does not authenticate a caller.
  5. Report targeted approaches through the appropriate military or employer security channel, particularly for personnel in sensitive positions.

A year of credit monitoring is useful, but an SSN does not become harmless when that subscription expires. The exposure calls for long-term caution, not panic—and certainly not blind trust in anyone claiming to be “DMDC support.”

Sources
 
Back
Top