Unknown hackers reached unencrypted Defense Department personnel files on just over 3 million people for about nine months, a department official said, while the FBI investigates a hacking group's claim to have stolen data on its own employees.

The Defense Manpower Data Center (DMDC) found a flaw in one of its file-sharing systems on 16 July, according to a notification letter dated 18 September. The exposed files cover 2.76 million living people and 294,000 who have died, a Defense Department official said.

Names, home addresses, Social Security numbers and job details appear in both the DMDC files and the FBI records, according to the DMDC letter and a Reuters analysis of data the hacking group ShinyHunters says it took from the bureau. Eric O'Neill, a former FBI counterintelligence operative, told Reuters the FBI file is "a foreign intelligence service goldmine."

US and Israeli forces began striking Iran on 28 February 2026, five months into the DMDC exposure. Iran-linked hackers have since sent threatening messages to US troops in the Gulf and published what they said were the names and phone numbers of 2,379 Marines.

Defense Department personnel records

DMDC holds more than 60 million records on active-duty troops, reservists, civilian employees, contractors, family members, retirees and veterans. The agency ties each of those people to the Common Access Card and credentials used to enter Defense Department networks, buildings and bases. Its website carries the line: "We make sure that the right people get access and the wrong people don't: security of identity information is paramount."

A small number of unauthorised users reached a server holding unencrypted files between October 2025 and 16 July 2026, according to the letter. Each exposed record held a Social Security number and at least one other item: name, date of birth, contact details, sex, race or military occupational specialty code.

A US defence official gave the department's account in a statement: "A Defense Manpower Data Center (DMDC) information system experienced unauthorized access of personally identifiable information by a small number of unauthorized users between October 2025 and July 2026. Upon discovery, DMDC immediately remediated the vulnerability."

DMDC patched the file-sharing system and brought it back online, the letter said. The letter went out 64 days after the flaw was found. Military Times first reported it on 24 September, and two defence officials confirmed to the outlet that the letter was authentic.

Two people familiar with the incident had put the number affected at about 4 million before the department released its figure of just over 3 million. The US military had 1.3 million active-duty service members in March.

Defense Department officials have not said who reached the files or why, and the letter names neither the file-sharing product nor the flaw. The department said it has no indication the data was misused. It has not said how it reached that conclusion, or whether any files were copied off the server.

Counterintelligence and the war with Iran

Justin Sherman, chief executive of Global Cyber Strategies, said the data would let an adversary "learn about or even target" defence personnel "based on their earnings, debts, marriages, spending habits, browsing activities, and worse." He said: "On its own, having personal data on potentially millions of service members exposed is dangerous as the US wages war on Iran."

Military occupational specialty codes record what each service member is trained to do, from infantry and intelligence analysis to cyber operations. Paired with a Social Security number, date of birth and home address, the codes let anyone holding the files sort millions of names by job and find where those people live.

Handala, a hacking group linked to Iran, sent WhatsApp messages to US service members in Bahrain in April. "Your identities are fully known to our missile units, and every move you make is under our surveillance," one message said. "Very soon, you will be targeted by our Shahed drones and Kheibar and Ghadeer missiles."

Handala published what it said were the names and phone numbers of 2,379 Marines in the Gulf on 28 April and claimed to hold their home addresses, family details and daily commutes. Many entries in the published sample were invalid, including incomplete phone numbers and military contract numbers in place of names.

Navy Secretary John Phelan warned sailors that adversaries were running a social engineering campaign against Navy personnel and their families. "These actors seek to psychologically influence [Navy] personnel and their families, and also seek to trick personnel into clicking on/opening potentially malicious links and files," he wrote.

Admiral Brad Cooper, head of US Central Command, sent a memo to troops deployed in the Middle East in late July explaining why their phones could be confiscated. Videos posted by troops of Iranian missile strikes on US bases carried GPS location data.

China's Salt Typhoon group held access to an Army National Guard network from March to December 2024 and took administrator credentials, network diagrams and personal information on service members, according to a June 2025 Department of Homeland Security memo. "Going forward, all U.S. forces must now assume their networks are compromised and will be degraded," Gary Barlet, a former Air National Guard member and public sector chief technology officer at Illumio, said after the memo was released.

The Office of Personnel Management lost records on more than 22 million government employees and applicants in 2015, including background investigation files for security clearances. The theft has been broadly attributed to China.

FBI jobs portal intrusion

ShinyHunters replaced the front page of FBIJobs.gov on 22 September with a notice saying the site had been seized, then sent samples of stolen records to journalists. The intrusion took place a day earlier, on 21 September, according to NBC News.

ShinyHunters said it holds two to three terabytes of data covering almost all FBI agents and job applicants. The group named the bureau's Criminal Justice, HR, Medlink, PEGA and PHIRE services as affected. None of those claims about scale has been verified.

FBI officials said they had not determined whether the breach came through a third party or the bureau's own network, and that they were working with the providers that support FBIJobs.gov. The bureau employs about 37,000 people.

A 5,000-line sample lists 14 staff in China-related roles, nine in Russia-related roles, three in Iran or Hezbollah intelligence work, 18 in intercept and surveillance units and 11 in human intelligence posts, a Reuters analysis found. Reuters matched details for more than 22 people against credit records and earlier leaks.

Three records in the sample reference the FBI's Remote Operations Unit, the team that builds exploits and tools to break into targets' devices, 404 Media found. Entries in the sample include home addresses, phone numbers and, for some staff, spouses' details. Hackers also showed Bloomberg files resembling health reports that list medical conditions and mental health history of named employees, which Bloomberg could not verify.

FBI management emailed all personnel on 23 September to say the bureau was investigating. A second message on 25 September told staff the bureau was working on the premise that their personal data may have been taken. Some employees said they first learned of the breach from news reports.

ShinyHunters said it attacked the bureau to force withdrawal of a 15 May FBI public service announcement. The announcement said the group sends threatening texts and calls to victims and their relatives, in some cases swats them, and falsely claims to hold compromising photos or videos that often do not exist.

ShinyHunters posted a seven-day countdown on its leak site, then wrote there: "we got what we wanted and we have a business to run and operate as usual." In a later statement the group wrote: "Since the very beginning of this event we have unequivocally and assiduously emphasised this is NOT extortion, this is NOT ransom, this is NOT financially motivated." On 28 September it said it would never publish the data.

PeopleSoft exploit and web shells

Oracle issued a security alert for CVE-2026-35273 on 10 June, after ShinyHunters had exploited the flaw as a zero-day from 27 May to 9 June, according to Google Threat Intelligence Group and Mandiant. The bug allows unauthenticated remote code execution in the PeopleSoft Environment Management Hub, known as PSEMHUB. Universities and colleges took most of the first wave, and about 100 organisations lost data in it, BleepingComputer wrote. Google tracks the group as UNC6240.

Mandiant reported on 26 September that ShinyHunters now requests the vulnerable endpoint as /%50SEMHUB/ instead of /PSEMHUB/. Many web application firewalls check the literal path before decoding it, while Oracle WebLogic decodes %50 to the letter P and routes the request through to the hub.

ShinyHunters first sends five to 15 POST requests carrying serialised Java objects, according to Mandiant. An unpatched server answers with its operating system type without writing a file or interrupting service, which tells the attackers the host can be exploited quietly.

Web shells named x.jsp, u.jsp and u2.jsp then land in the PSEMHUB application folder. The x.jsp shell runs commands sent in hexadecimal and rebuilds the string "/bin/sh" from character codes so signature scanners miss it. The u.jsp and u2.jsp shells upload larger files in 150 KB chunks, which slips past request size limits.

Ple64.exe, a 5.2 MB file disguised as an installer for the Light Alloy media player, carries a backdoor Google calls SIDEEYE. The file was signed with a valid Extended Validation certificate issued through Sectigo, which has since revoked it. SIDEEYE loads in memory, steals credentials saved in browsers and desktop applications, and gives the attackers a reverse shell and proxy.

Neo-reGeorg, an open-source tunnelling toolkit, carries the attackers' traffic from the web server into internal networks. The group also installs MeshAgent, a legitimate remote management tool, pointed at domains built to look like Microsoft services. A quarter of the commands Mandiant observed ran as root or NT Authority\SYSTEM, giving full control of the host.

Google said the renewed wave has put web shells on dozens of systems worldwide, in higher education, technology, IT services, healthcare, agriculture, transport and government. ShinyHunters told BleepingComputer it used the encoding bypass against FBI Jobs, and said it also exploited a new flaw in the same component to move into the bureau's AWS GovCloud infrastructure. Neither claim has been independently verified.

Dutch arrest and FBI warning

Dutch police announced on 29 September that they had arrested a 24-year-old Amsterdam man on 15 September on suspicion of a role in ShinyHunters and participation in a criminal organisation. FBI Director Kash Patel described him as one of the group's alleged leaders.

Dutch police said the suspect's laptop held details of two murders that were to be committed abroad, with indications that he ordered them. The Rotterdam District Court kept him in pretrial detention for at least another 90 days, and police said further arrests have not been ruled out.

FBI officials have not tied the suspect to the bureau's own breach, which took place six days after his arrest. Dutch police said he was not arrested in their investigation of the ShinyHunters breach of the telecom provider Odido.

Brett Leatherman, assistant director of the FBI Cyber Division, said in a video that the suspect and alleged co-conspirators had breached more than 140 organisations since 2025 and collected at least $70 million in extortion payments. The group often goes after single sign-on accounts, third-party vendors and cloud platforms including Salesforce and Snowflake. "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left," Leatherman said. "You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."

Federal breaches since January 2025

Microsoft told the Office of the Comptroller of the Currency on 11 February 2025, three weeks into Donald Trump's second term, that intruders were inside its email system. Using a compromised administrator account, they had read about 150,000 emails from 103 bank regulators' mailboxes since May 2023. The Treasury Department bureau declared a major incident in April 2025.

Michael Waltz, then national security adviser, added Jeffrey Goldberg, editor of The Atlantic, to a Signal group chat in March 2025 in which Defense Secretary Pete Hegseth posted targets, timing and aircraft for US strikes on the Houthis in Yemen. The Defense Department inspector general found in December 2025 that Hegseth risked the safety of US service members by sharing the information on Signal and broke department rules on using personal phones for official business. A department spokesperson wrote that the review was "a TOTAL exoneration of Secretary Hegseth."

TeleMessage, whose modified Signal app Waltz was photographed using, suspended its service on 5 May 2025 after a hacker took data including messages linked to US Customs and Border Protection. Researchers found the app stored chat logs in plain text and held hardcoded credentials in its source code.

Hackers entered Federal Emergency Management Agency servers on 22 June 2025 through the Citrix flaw known as CitrixBleed 2 and took employee data from FEMA and Customs and Border Protection. Homeland Security Secretary Kristi Noem fired 24 FEMA technology staff on 29 August, including its top technology and cybersecurity officers. Homeland Security officials cited "an agency-wide lack of multi-factor authentication" and failures to fix known vulnerabilities.

Attackers exploited a Microsoft SharePoint zero-day from 18 July 2025 and reached systems at the Department of Energy, including the National Nuclear Security Administration, which maintains the US nuclear stockpile. The Energy Department said "a very small number of systems were impacted" and it found no evidence classified information was compromised. Microsoft named three China-based groups exploiting the flaw: Linen Typhoon, Violet Typhoon and Storm-2603.

Russian hackers were behind a breach of the federal judiciary's electronic case filing system and PACER disclosed in August 2025, according to investigators. The intruders sought sealed records, including some with overseas connections, in at least eight district courts. "The Judiciary is a high-value target for malicious actors and cyber criminals seeking to misappropriate confidential information," Judge Michael Scudder, who chairs the Judicial Conference information technology committee, said.

Chuck Borges, the Social Security Administration's chief data officer, filed a whistleblower complaint on 26 August 2025 alleging that Department of Government Efficiency staff had made "effectively a live copy" of the NUMIDENT database in an insecure cloud environment. The database holds names, birth dates, addresses and family details from more than 300 million Social Security card applications. The agency said the data was "walled off from the Internet."

Justice Department lawyer Elizabeth Shapiro wrote in a court filing on 20 January 2026 that two Department of Government Efficiency staff may have shared Social Security data with an advocacy group whose "stated aim was to find evidence of voter fraud and to overturn election results in certain States." The filing said the data had gone to unapproved third-party servers.

F5, whose BIG-IP devices handle traffic for many federal networks, disclosed on 15 October 2025 that a China-linked group had spent about 12 months inside its development systems and stolen source code and details of unfixed flaws. The Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 26-01, citing an "imminent threat to federal networks."

The Congressional Budget Office said on 7 November 2025 that it had contained a breach, and the Senate Sergeant at Arms told staff not to click links in emails from its accounts. A US official told CNN that Chinese state hackers were suspected. The office said it had "implemented additional monitoring and new security controls."

FBI investigators opened an inquiry on 17 February 2026 into abnormal activity on the network the bureau uses to manage wiretaps and surveillance. The Justice Department declared it a major incident under the Federal Information Security Modernization Act on 23 March. The system held electronic surveillance data, including phone numbers of surveillance targets, and personal information on subjects of FBI investigations.

An employee of Nightwing, a CISA contractor, left administrative keys to three AWS GovCloud servers and plaintext passwords for dozens of internal CISA systems in a public GitHub repository from 13 November 2025 until it was found on 15 May 2026. CISA said there was "no indication that any sensitive data was compromised."

Unknown attackers breached the Homeland Security Information Network, which federal, state, local and private partners use to share unclassified intelligence, between late May and early June 2026. Material on the system covered World Cup security planning. The department said "there is no indication that classified networks were impacted." Senator Mark Warner, the top Democrat on the Senate Intelligence Committee, said the exposure put national security at risk.

The Bureau of Alcohol, Tobacco, Firearms and Explosives declared a major incident on 27 August 2026 after the Qilin ransomware gang listed it on its leak site. The breached system, separate from the bureau's main network, held information on targets of ATF investigations.

CISA staffing

CISA lost about a third of its workforce during Trump's first year back in office and has had no Senate-confirmed director since January 2025. The agency cut its counter-ransomware initiative and parts of its election security team, and hundreds of its staff were reassigned to support immigration enforcement. Madhu Gottumukkala was its acting director as of February 2026.

The Privacy Act of 1974 requires federal agencies to protect personal records with administrative, technical and physical safeguards against anticipated threats to their security. The DMDC letter states the exposed files were unencrypted.

Federal Information Security Modernization Act rules and Office of Management and Budget guidance class any breach that exposes significant amounts of personal information as a major incident, and agencies must report major incidents to Congress within seven days.

DMDC's letter offers affected people one year of free credit monitoring and identity restoration through IDX, a private contractor, reached through a Defense Department site linked in the notice.

Mandiant told PeopleSoft operators to install the CVE-2026-35273 update instead of relying on firewall rules, and to disable EMHub or remove PSEMHUB where it is not needed. It also told them to search WebLogic access logs for requests to /PSEMHUB/ and encoded variants such as /%50SEMHUB/, check the PSEMHUB.war folder for x.jsp, u.jsp, tunnel.jsp, tunnel.jspx and Ple64.exe, and rotate database, Integration Broker and cloud credentials reachable from the PeopleSoft web tier.ders should go to the Mandiant post.