
A breach of the Pentagon’s personnel database exposed Social Security numbers and other sensitive information about current and former military personnel, raising fears about how the data could be used.
Unauthorized users gained access to a Defense Manpower Data Center server last October, but the Pentagon did not discover or fix the problem until July, according to a notification letter reviewed by CNN.
The Pentagon said in its letter dated this month that it “does not have any indications of misuse” of the information exposed from the breach.
“But the breached data is a potential goldmine for foreign intelligence services looking to track US military personnel, or cybercriminals looking to extort them (were they to acquire the data),” CNN reported, citing experts.
Justin Sherman, CEO of Global Cyber Strategies, warned that someone could pair the data with commercial records to “learn about or even target [defense personnel] based on their earnings, debts, marriages, spending habits, browsing activities, and worse.”
According to CNN, the records were not encrypted, and the number of people affected remains unclear. But Military Times has reported that as many as four million Defense Department personnel could be affected.
It is also unclear who the culprit behind the breach is, CNN reported.
Sherman emphasized the danger of exposed data involving potentially millions of service members, especially “as the US wages war on Iran and is in competition with multiple other governments.”
“If a foreign adversary was to get this kind of data trove, it could enable phishing, profiling, foreign intel approaches, and much more,” he said.





