A notification dated September 18 and attributed to the Defense Manpower Data Center (DMDC) describes unauthorized access to files containing personal information from October 2025 through July 16, 2026. The center says it discovered and fixed the vulnerability on July 16. News outlets citing Defense Department officials estimate that 2.76 million living people and 294,000 deceased people were affected.
The notification says the files contained unencrypted personal information. Depending on the record, it could include Social Security numbers, names, dates of birth, contact details and military job information. Officials cited in reporting say they have not detected misuse so far.
What is confirmed and what is not
The DMDC sent individual letters; Military Times reviewed one and confirmed its authenticity with Defense officials. ABC News later reported an aggregate figure attributed to a US official. Early totals varied as the scope became clearer through notifications.
The sources reviewed do not identify who accessed the files or publicly describe the file-sharing product or technical flaw. It is therefore more accurate to say unauthorized access was reported than to claim who carried it out or that all the data was published.
Verify a notice without being misled
Recipients should verify a letter using official DMDC or Department of Defense contact details. Do not send a Social Security number in response to an unexpected email or text. Use the credit-monitoring service described in an authentic notice and report unusual activity to the relevant organizations.
Organizations holding sensitive data can also review permissions on shared storage, retention periods and download logging. A valid account's access to a service does not mean a particular record was viewed.
How Soclyde fits
This exposure concerns personal information held by an administrative system, not Soclyde vaults. Soclyde cannot prevent or undo it; the sources do not report that passwords were involved. For team service accounts, its vault can help organize credentials, but it does not replace protections against identity theft.
The takeaway
The DMDC fixed the vulnerability after discovering unauthorized access. People who receive notices should verify them and monitor their accounts without assuming the information has already been misused. Read the team password management guide or contact Soclyde.



