PŽ
    /
    Zpět na blog
    Security Sunday

    9 months in Pentagon systems


    9 months in Pentagon systems

    image

    Today we’re talking about one of the biggest security incidents in the history of the US military.

    From October 2025 to July 2026, unknown attackers had access to the personal data of more than three million people connected to the US military, including Social Security numbers. That’s roughly nine months before anyone noticed.

    The Pentagon isn’t alone. Just a few days earlier, on September 22, the ShinyHunters group claimed responsibility for an attack on the FBI. I covered that incident in the previous episode.

    We’ll go through what happened, what data leaked, and why it’s a national security problem.

    Hi, my name is Patrik Žák, and welcome to Security Sunday.

    What happened

    The affected institution is the Defense Manpower Data Center, or DMDC for short. It’s a support organization of the US Department of Defense that has been operating since 1974.

    DMDC manages more than sixty million records on service members, civilian employees, contractors, family members, and veterans.

    DMDC describes itself as the department’s central source for identifying and authenticating people, both during their time with the department and after it ends.

    The attackers got in through a security vulnerability in a file-sharing system.

    According to Pentagon officials, the breach affects more than three million people. Military Times, citing two sources familiar with the incident, puts the estimate as high as four million. The official figure, however, remains three million for now.

    What data leaked

    According to the notification letters sent to affected people, it varies from person to person. Some letters indicate that the attackers obtained Social Security numbers, names, dates of birth, contact details, sex, race, military occupational specialty, and other data from military personnel records.

    Roughly nine months passed between the start of the attack and its discovery, and another two months between discovery and the first letters.

    Notably, the files containing this data were not encrypted, even though encrypting sensitive personal data is standard security practice.

    What’s confirmed and what isn’t

    It’s important to separate what’s confirmed from what isn’t.

    Confirmed: the entry point was a vulnerability in a file-sharing system, the data was unencrypted, and the vulnerability has been fixed.

    The Pentagon hasn’t disclosed which specific vulnerability it was. It also declined to say who is behind the attack, or even whether it was targeted. According to CNN, the perpetrator remains unknown.

    The Pentagon also says it has no indication so far that the leaked data has been misused. That’s good news, but treat it with caution. The fact that we don’t know of any misuse today doesn’t mean it won’t happen. An attacker who had access for nine months and went unnoticed doesn’t have to use the data right away.

    What can be done with this data

    Let’s look at what this kind of data can be used for.

    Identity theft

    In the US, the Social Security number is a key identifier. Combined with a name and date of birth, it is often enough for an attacker to open a loan or an account in someone else’s name. That’s why the Pentagon is offering victims credit monitoring.

    Targeted phishing and blackmail

    Security experts quoted by CNN warn that this data is a “potential gold mine” for foreign intelligence services looking to track US service members, and for cybercriminals who might want to blackmail them.

    Analysts at OODA Loop warn that the data could be used for identity theft, targeted phishing campaigns, and extortion of military personnel.

    Combining with other data sources

    Justin Sherman, CEO of Global Cyber Strategies, pointed to another risk. Quote: “If a foreign adversary got hold of a dataset like this, it could enable phishing, profiling, and much more.”

    Counterintelligence risk

    According to CNN, the incident is raising counterintelligence concerns among national security experts.

    Keep in mind that military occupational specialties leaked too. An attacker can therefore build a list of people with a specific specialization, along with their contact details. A person whom an adversary knows to be in financial trouble is a classic recruitment target.

    We don’t yet know who carried out the attack or whether the data reached a foreign power. We’re describing risks that experts warn about, not confirmed misuse.

    DMDC’s response

    DMDC says it launched its incident response process immediately after discovery, in line with agency rules. It fixed the vulnerability and brought the system back online. It also says it is taking steps to assess and strengthen the system’s security.

    Whether it’s this attack or last week’s attack on the FBI, the pattern is clear. Government personnel systems are an exceptionally valuable target for attackers, because they concentrate exactly the data attackers need in one place.

    Takeaways

    What should you take away from this if you manage any system that holds personal data?

    • Encrypt data at rest. Had the files on the server been encrypted, the breach would have had a much smaller impact.
    • Monitor data access. Nine months between intrusion and discovery shows that prevention alone isn’t enough. You need to monitor who accesses data and in what volume.
    • Keep file-sharing systems under control. They’re a favorite entry point for attackers. If you run them, keep them inventoried, patched, and monitored.
    • Minimize data. What isn’t in the system can’t leak.

    Summary

    To sum up: more than three million records, unencrypted data, roughly nine months undetected, and a perpetrator who is still unknown. Misuse of the data hasn’t been confirmed yet, but experts warn that it’s valuable loot for both intelligence services and cybercriminals.

    ShinyHunters Under Pressure

    In less than three weeks, law enforcement has dealt two significant blows to ShinyHunters, a group that specializes in data theft and extortion and recently boasted of breaching FBI systems. On September 15, Dutch police arrested a 24-year-old man from Amsterdam as part of the ShinyHunters investigation, and FBI Director Kash Patel later described him as one of the group’s alleged leaders.

    Then on October 3, Reuters, citing three sources familiar with the matter, reported that another suspected member, Saif al-Din Khader, allegedly operating under the alias “Rey,” was arrested in Jordan on September 29 and is helping the FBI and other agencies identify the other hackers.

    Debian Fixes 1,313 Vulnerabilities

    Debian has released one of its largest kernel security updates to date. Advisory DSA-6528–1, published on September 29, 2026, by Debian security team member Salvatore Bonaccorso, fixes 1,313 vulnerabilities in the Linux kernel for the current stable release, Debian 13 “Trixie.” The fixes are included in the linux package version 6.12.111-1, and Debian recommends that all users upgrade their kernel packages.

    The numbers need context, though. This is one advisory for one source package, not 1,313 separate packages or 1,313 confirmed attacks. We counted the identifiers in the advisory: 1,295 of them are from 2026, 15 from 2025, and 3 from 2024. Debian describes the possible impact only in general terms: privilege escalation, denial of service (DoS), or information leaks.

    Google Launches Gemini 4 Argon

    On September 30, Google DeepMind unveiled Gemini 4 Argon, a new frontier model designed for long-running, complex tasks in software development, law and finance, and cyber defense.

    The new flagship model isn’t publicly available yet. It is going first to a limited group of trusted cyber defenders through the Fairwind program, a closed-access program Google launched on September 2 alongside the Gemini 3.8 Flash Cyber model. Fairwind is aimed at government institutions, critical infrastructure operators, and key technology platforms.

    © 2026 Patrik Žák. Všechna práva vyhrazena.