The US Defense Manpower Data Center has begun notifying people that unauthorized users accessed files containing personal information on one of its file-sharing servers. Reporting based on the agency’s notification and a Defense Department official places the affected population at roughly three million living and deceased individuals.
The exposed server held unencrypted personnel data
The notification says a vulnerability discovered on July 16, 2026 allowed unauthorized access to files. Investigators found that a small number of users had accessed the server between October 2025 and discovery. The center patched the file-sharing system and restored service after identifying the weakness.
Records varied by person and could include names, Social Security numbers, dates of birth, contact details, demographic information and military occupational specialties. The agency said it had not identified misuse when notices were issued.
Long exposure windows increase investigation demands
Incident teams must determine which files were reached, which identities were exposed and whether access persisted across credential or server changes. Sensitive government repositories require encryption, least privilege and alerting on abnormal file access. SectechMedia follows related controls in its cybersecurity coverage.

Leave a Reply