Two Federal Agency Hacks in One Month Expose Military and FBI Personnel Data


Two Federal Agency Hacks in One Month Expose Military and FBI Personnel Data

 

A breach at the Defense Manpower Data Center has compromised the personal records of 2.8 million living individuals, the Pentagon says, with more than 2 million current and former military members now being notified that their information was stolen. It is the second major breach of sensitive US government personnel data in recent months, following a reported hack of FBI systems, and it is the kind of story this site's consumer reporter flags early so readers understand their exposure before scammers or foreign adversaries can act on it.

According to a notification letter posted to Reddit, the stolen Defense Manpower Data Center records include Social Security numbers, names, addresses, sex, race, and occupational specialty. That last detail could be especially useful to foreign intelligence agencies trying to identify high-value military personnel. The hackers reportedly gained access to the system starting last October and maintained that access for months before being discovered. The Defense Manpower Data Center says it handles more than 60 million Defense Department "person records," covering military, civilian, contractor, retiree, and veteran personnel along with their families. The Pentagon has not said how the attackers got in, whether officials have been in contact with those responsible, or whether any ransom was demanded. Officials say the stolen data has not been misused, but have not explained how they reached that conclusion.

The breach comes a month after the ransomware group ShinyHunters claimed it hacked FBI systems and stole records on thousands of current or former agency employees. Reuters reported some of the exposed job titles were tied to investigations of China or Russia. ShinyHunters says it has no plans to release the information, though the article notes a criminal group's promises carry little weight, and its security is unlikely to hold up against nation-state hackers. FBI Cyber Division Assistant Director Brett Leatherman this week urged members of the group to surrender, saying, "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours." His comment followed the arrest of a ShinyHunters member by Dutch police.


BookMasher

Together, the two breaches are described as one of the largest potential espionage hauls since the 2015 Office of Personnel Management hack, in which China-linked hackers obtained 22.1 million records, including fingerprint scans.

How to spot it

  • Notification letters describing stolen personnel records, including Social Security numbers, names, addresses, sex, race, and occupational specialty
  • Claims from criminal groups like ShinyHunters about stolen federal employee data
  • Official notices referencing unexplained or undisclosed breach methods

What to do if it happened to you

  • Review any official notification letter from the Pentagon or Defense Manpower Data Center for details on what information was exposed
  • Follow guidance from the Department of Defense regarding affected personnel records
  • Watch for updates from the FBI on the ShinyHunters investigation, including Assistant Director Brett Leatherman's public call for group members to come forward

Source: Ars Technica