What can we learn from the data breaches of FBI and Pentagon personnel records?
By now you've probably heard about the two major data breaches of U.S. government personnel records discovered weeks apart, in what some are seeing as dueling counterintelligence nightmares.
The breach at the U.S. military's human resources unit, the Defense Manpower Data Center (DMDC), allowed hackers to steal the personal data of about 3 million current and former military service members and their families, including Social Security numbers. The "unauthorized users" (plural!) went undetected for nine months until July, and data breach notifications began to go out to affected individuals in the past few weeks. It's not yet known who is behind the data thefts.
The second breach hit the FBI in September, in which a typically financially motivated cybercriminal hacking group called the ShinyHunters stole personal data on "almost all FBI agents" and the bureau's applicants. The data contained highly sensitive information, like job assignments, including foreign surveillance and counterespionage, as well as details of blood and urine samples, and psychiatric assessments. The hackers said the theft was not extortion, and that they wouldn't publish the FBI's stolen data.
The incidents are almost certainly separate from each other, but come as the U.S. fears that the data could still end up in the hands of adversaries, who might use it to extort U.S. military and federal staff into handing over government information.
The feeling is very much "first time?" energy for some of the former federal workers, whose highly sensitive personnel records were stolen during a previous 2015 breach of the U.S. government's human resources department, the U.S. Office of Personnel Management, by suspected Chinese hackers.
Now, much of the discussion about the two recent hacks is focused on how they happened. Actually, a lot went wrong. These breaches include data that may affect some people for years to come, if not their entire lives.
I've spent a few days perusing both the DMDC data breach notice and what we know from the public reporting about the FBI's breach, including my own, to understand what we can learn from these avoidable mistakes.
~this week in security~ is my weekly cybersecurity newsletter and blog supported by readers like you. Please consider signing up for a paid subscription starting at $10/month for access to exclusive articles, analysis, and more.
Or, you can submit a one-time tip or gift a paid subscription to show your support!
Recent stories include: Hackers are mass-exploiting Citrix NetScaler systems in ongoing cyberattacks | How a phone call allowed a hacker to steal millions of people's personal data | A breach of over 150 million U.S. and Canadian driver's license photos is an anonymity disaster | Apple opens the door to a nightmare world of always-listening tech | How residential proxy networks are hiding hackers in your home | Vigilantism comes for Flock
It's risky to hold sensitive data for long periods of time
Human resources systems, like the FBI's hacked Oracle PeopleSoft server and the DMDC's data banks, can store reams of personnel data going back decades. As such, these systems can be rich targets for both espionage-driven hackers and cybercriminals.
One person, who was notified by the Pentagon that their information was taken in the DMDC breach, told me that they retired from the Air Force in the early 2000s — so this data goes back a long time. The DMDC breach could have been (and may be) far bigger, as the unit stores over 60 million records, including information about family members. It appears that (so far) only a file transfer system on the DMDC's network was hacked, potentially limiting the scope of the data theft.
The FBI's breach, meanwhile, is likely to affect the majority of the bureau's 38,000 personnel, including actively serving agents and other support staff.
Encrypt all the things, and keep your keys separate
DMDC confirmed that the hackers compromised the unspecified file transfer tool used to store the 3 million unencrypted military personnel records. It's not clear why the data was unencrypted. If the data was encrypted, it's critical to ensure that the private keys or admin accounts needed to unscramble the data are kept entirely separate so that data can't become readable if it's stolen or accessed.
Financially motivated hackers have targeted enterprise file-transfer tools in the past because the organizations using them to securely share large datasets over the internet, such as customer data, often forget to delete the data once it's been sent. This ends up leaving behind troves of sensitive user data ready to be stolen by hackers down the line.
Keep your web-facing systems protected and patched
The ShinyHunters hackers told Bleeping Computer that they hacked the FBI's careers website and defaced the bureau's job application portal, then from there broke into its Oracle PeopleSoft server hosted on the backend. Reuters ($) reports that the PeopleSoft server hadn't yet received a security patch from June, allowing the hackers to break in and steal the data stored within.
The FBI blamed a contractor working for outsourcing giant Accenture who didn't patch the system they were overseeing, but as I've said before, big hacks are almost never a single person's fault; the FBI is ultimately responsible for its own systems and employees' data.
DMDC hasn't disclosed how its file transfer tool was compromised. Given that the Pentagon's network is meant to be pretty secure and locked down from the outside world, I would probably bet that hackers breached a public-facing commercial tool used by the DMDC. That said, mistakes sometimes happen and sensitive military systems have been exposed to the public web. (I asked the Pentagon about the file transfer tool, such as who is the vendor, but a spokesperson did not say.)
Logging and monitoring for data anomalies can save you
The DMDC breach went on for months and nobody noticed. The breaches went back to at least October 2025 until the hackers' access was cut off in July 2026. Ensuring that there is logging and continuous monitoring, such as who is accessing files or checking for spikes in bandwidth of data leaving a network, can help raise the alarm to suspected data breaches. This is also something to consider for third-party software; if a commercial service doesn't maintain an audit trail, it's probably not very good software.
The bottom line is that there is no such thing as perfect or absolute security, but the stakes are inherently higher in government and the military. These incidents come soon after extensive cuts and layoffs across the federal government — including cybersecurity agency CISA, and the National Security Agency, which is tasked with protecting classified and defense systems — have decimated its cybersecurity workforce.
Clearly these incidents have shown that the federal government needs more cybersecurity talent, and not less.
Thank you so much for reading ~this week in security~. If you like this article, please share a link on your social media! Reach out with any feedback or comments about this article: this@weekinsecurity.com.