Skip to content
Breaking:

Dual Federal Data Breaches Expose Records of 2.8 Million Military Personnel and FBI Staff

Intrusions at the Defense Manpower Data Center and the FBI mark one of the most severe federal cyber leaks since the 2015 OPM hack.

By The Company Wire3 min read
Share
Department of Defense — Dual Federal Data Breaches Expose Records of 2.8 Million Military Personnel and FBI Staff
Department of Defense — Dual Federal Data Breaches Expose Records of 2.8 Million Military Personnel and FBI Staff. Photo: Ars Technica.

The United States Department of Defense has begun notifying approximately 2.8 million living current and former military personnel that their sensitive personal files were compromised during a monthslong cyber intrusion on an administrative network, Ars Technica reported. The breach targeted a system operated by the Defense Manpower Data Center, which collates personnel management information across the armed forces. The incident marks the second major breach in recent months to expose sensitive federal personnel records.

Details of the compromised data surfaced after an official notification letter sent to an affected service member was shared on Reddit. According to the letter, the exposed files contained Social Security numbers, names, physical addresses, sex, race, and military occupational specialties. Counterintelligence and cybersecurity analysts note that occupational specialty data is particularly sensitive, as foreign intelligence agencies could use it to identify and track high-value personnel.

According to the Pentagon, unauthorized actors gained access to the Defense Manpower Data Center system starting last October. The agency manages more than 60 million records across the defense sector, covering active-duty military, civilian staff, contractors, retirees, veterans, and family members.

The Pentagon intrusion follows another significant federal security incident reported last month. The cybercrime and ransomware group ShinyHunters claimed responsibility for infiltrating FBI computer systems and stealing records belonging to thousands of current and former employees. Reuters reported that those stolen records contained job titles, including positions connected to investigations into China and Russia.

While ShinyHunters claimed it does not plan to release the stolen FBI data, security analysts emphasize that promises from criminal extortion groups carry little weight. Furthermore, criminal syndicates' own infrastructure remains vulnerable to intrusion by foreign intelligence services seeking access to stolen government datasets.

Law enforcement scrutiny on ShinyHunters intensified recently after Dutch police arrested a suspected member of the group. Speaking after the arrest, FBI Cyber Division Assistant Director Brett Leatherman publicly urged remaining members to surrender.

"The longer you stay in this, the more we learn about you," Leatherman said. "You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."

Combined, the breaches at the Defense Department and the FBI constitute one of the largest potential espionage hauls since the 2015 hack of the U.S. Office of Personnel Management. In that breach, state-sponsored hackers linked to China acquired 22.1 million records associated with federal employees and background check applicants, including personal histories and fingerprint scans.

The Defense Department has not disclosed how attackers breached its systems, whether officials have communicated with those responsible, or whether attackers issued ransom demands. Pentagon officials have stated that the stolen military records have not been misused, though they have not detailed the technical basis for that assessment.

Sources

  1. Ars Technica

Company: Department of Defense

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.