Defense Manpower Data Center (DMDC) hit by network compromise
Incident
Summary
Hide ▲
Show ▼
The Defense Manpower Data Center (DMDC) disclosed a breach of the Pentagon human resources management system that exposed sensitive personnel data for more than 3 million people. The compromise involved unauthorized access through file-sharing systems and put PII and other military records at risk.
Related Happenings
FBI disrupts quartermaster infrastructure for Chinese espionage
Law Enforcement
H score33
First: 26.08.2026 17:17
Last: 26.08.2026 17:17
Sources 1
About this happening:
FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...
FBI disrupts quartermaster infrastructure for Chinese espionage
Law EnforcementAbout this happening: FBI disrupted infrastructure used by a technical quartermaster that enabled Chinese cyber espionage, removing reconnaissance, proxy management, and routing...
FortiBleed Fortinet/FortiGate VPN credential leak
Data Leak
H score80
First: 17.06.2026 18:12
Last: 17.06.2026 18:12
Sources 1
About this happening:
FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
FortiBleed Fortinet/FortiGate VPN credential leak
Data LeakAbout this happening: FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
Latest development: 19.06.2026 09:47
CISA urged Fortinet customers to secure FortiGate appliances after nearly 74,000 firewall and VPN credentials were exposed in the FortiBleed leak. The agency advised affected owners to terminate SSL VPN and administrative sessions, reset VPN and administrative passwords, enable phishing-resistant multifactor authentication, review logs for unauthorized access or lateral movement, store admin credentials with PBKDF2, restrict firewall management interfaces from public internet access, and remove unauthorized accounts.
North Korean remote IT worker scam operation targeting American companies
Campaign
H score41
First: 16.04.2026 19:00
Last: 16.04.2026 19:00
Sources 1
About this happening:
A long-running North Korean remote IT worker scam operation used stolen identities and fake placements to embed operators inside more than 100 American companies. The...
North Korean remote IT worker scam operation targeting American companies
CampaignAbout this happening: A long-running North Korean remote IT worker scam operation used stolen identities and fake placements to embed operators inside more than 100 American companies. The...
Timeline
-
01.10.2026 12:44 2 articles · 2h ago
Defense Manpower Data Center notifies military personnel of Pentagon data breach
Initial DisclosureDMDC notified affected military personnel that hackers breached the Pentagon human resources management system in October 2025 and that a small number of unauthorized users accessed sensitive personnel data, including personally identifiable information, between October 2025 and July 2026 by exploiting a vulnerability in file-sharing systems. Pentagon officials said the breach affects more than 3 million people, and DMDC said it immediately initiated privacy and cybersecurity incident response actions and is offering 12 months of free credit monitoring through IDX.
Show sources
- Hackers stole Pentagon personnel records of over 3 million people — www.bleepingcomputer.com — 01.10.2026 12:44
- Hackers stole Pentagon personnel records of over 3 million people — www.bleepingcomputer.com — 01.10.2026 12:44