There are few traditions more sacred in the American military than mandatory cyber training. Somewhere, right now, a staff sergeant is clicking through a government module explaining that personally identifiable information is precious, passwords are sacred, suspicious links are dangerous, and leaving your CAC unattended will apparently cause Beijing to annex Ohio.
Then the Pentagon misplaced the plot.
The Defense Manpower Data Center says unauthorized users accessed files containing unencrypted personally identifiable information between October 2025 and July 2026. The exposed information included Social Security numbers and, depending on the person, names, birth dates, contact information, demographic information, and military occupational data. Defense officials later put the count at 2.76 million living people and about 294,000 dead people.
That’s more than three million people whose personal information got an all-expenses-paid trip through the government’s idea of cybersecurity.
The dead were included, which is thoughtful. Nothing says full-spectrum operations like creating identity-theft anxiety for people who have already completed their final out-processing.
DMDC discovered the vulnerability on July 16. Notification letters went out in September. The department says it has no indication the information has been misused. Excellent. That sentence has the emotional utility of your mechanic saying, “The brakes fell off, but so far we have no indication you’ve hit a tree.”
Affected people are being offered one year of credit monitoring and identity-restoration services.
One year.
A Social Security number generally follows you for life. The government’s solution to exposing it is twelve months of somebody watching Experian like a Labrador staring through a screen door.
After that, apparently, good luck and thank you for your service.
The comedy here would be impossible to write if the institution hadn’t already written it for us. DoD’s own Cyber Awareness Challenge teaches users to protect personally identifiable information. The course exists because one careless click, one exposed record, one unsecured system, one human shortcut can matter. Individual users are trained, tested, warned, monitored, and periodically treated like they’re carrying the nuclear football because they opened Outlook before coffee.
Yet millions of personnel records reportedly sat in files that unauthorized users could access, and the adjective attached to those files is “unencrypted.”
Somewhere a specialist who once received a counseling statement for leaving a CAC in a keyboard should be allowed to laugh until a flag officer becomes uncomfortable.
This isn’t an argument against cyber training. The training is necessary. The insult lies in demanding exquisite discipline from the individual while institutional systems are allowed to fail at industrial scale.
Military culture understands accountability perfectly when accountability travels downhill.
Private loses sensitive paperwork? Counseling.
Sergeant ignores procedure? Investigation.
Captain screws up? Evaluation report.
A database exposes millions of identities for months? Please enjoy twelve complimentary months of monitoring.
As if the breach needed backup singers, the Government Accountability Office reported in late September that three of the 18 major DoD IT programs it reviewed lacked a strategy for reducing cybersecurity threats. Seven programs reported that staff either had not received, or were unaware of, training to recognize and report signs of fraud or tampering in IT systems.
Apparently the PowerPoint achieved deterrence before the cybersecurity strategy did.
The phrase “small number of unauthorized users” has also been doing magnificent work in official descriptions. “Small” is comforting when discussing kindergarten classes, tumors, and bar tabs. It becomes considerably less reassuring when the small group has access to millions of personnel records.
And this goes beyond somebody opening a credit card in your name. Military occupational information combined with names, contact details, birth dates, and other identifiers has potential counterintelligence value. A hostile intelligence service doesn’t need a dossier wrapped in red string and stamped TOP SECRET when ordinary administrative data can help identify who does what, where they fit, and which social-engineering pitch might work.
That is why this deserves more than a patch, a letter, and the bureaucratic equivalent of a coupon.
Sensitive personnel data should be encrypted at rest and protected at the field level where feasible, especially Social Security numbers. Access should be tightly segmented, logged, time-limited, and based on actual job need.
The government should also stop using Social Security numbers as if they were universal luggage tags. Tokenize them. Mask them. Minimize where they’re stored. Eliminate unnecessary duplication. Every database that doesn’t need the permanent identifier shouldn’t possess it merely because federal computing has spent decades confusing “we’ve always done it” with architecture.
Breach response should include an independent technical review whose findings become public once operationally safe. We need to know what failed, how long access persisted, what controls missed it, and which changes were independently verified afterward. “We patched it” is a sentence. It isn’t an accountability system.
People whose permanent identifiers were exposed also deserve identity protection measured against the lifetime of the risk. One year is theater. If the government exposed the credential, the government should carry the protection burden far longer.
Finally, cybersecurity leadership should face the same principle every junior service member already understands.
Authority and responsibility travel together.
If leaders own the system, they own the standard.
The Pentagon asks service members to protect information because adversaries are patient, creative, and relentless.
Fair enough.
It would be reassuring if the Pentagon occasionally took its own training.
Sources for anyone whose annual training slide still says vigilance matters
- Military Times, Military personnel data exposed in breach, agency warns Military Times article
- ABC News, Pentagon breach exposed sensitive data on nearly 3 million people ABC News article
- Federal News Network, More than 3 million people affected by military data breach Federal News Network article
- DoD Cyber Exchange, Cyber Awareness Challenge 2025 DoD Cyber Exchange training page
- U.S. Government Accountability Office, IT Systems Annual Assessment DOD Should Improve IT Fraud Risk Management Practices GAO report
- U.S. Government Accountability Office, Information Environment DOD Needs to Address Security Risks of Publicly Accessible Information GAO report
_____________________________
Tammy Pondsmith studies federal competence the way coroners study unexplained deaths, after the body arrives and everyone in charge insists the paperwork looks terrific.
As the Voice of the Veteran Community, The Havok Journal seeks to publish a variety of perspectives on a number of sensitive subjects. Unless specifically noted otherwise, nothing we publish is an official point of view of The Havok Journal or any part of the U.S. government.
Buy Me A Coffee
The Havok Journal seeks to serve as a voice of the Veteran and First Responder communities through a focus on current affairs and articles of interest to the public in general, and the veteran community in particular. We strive to offer timely, current, and informative content, with the occasional piece focused on entertainment. We are continually expanding and striving to improve the readers’ experience.
© 2026 The Havok Journal
The Havok Journal welcomes re-posting of our original content as long as it is done in compliance with our Terms of Use.