Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Two Federal Breaches Expose Millions of Sensitive Records in Rapid Succession

Дата публикации: 02-10-2026 16:32:17

Breaches at the Pentagon and FBI exposed SSNs, military specialties, medical records and unit assignments for millions. Nine-month undetected access at Defense Manpower Data Center and a ShinyHunters zero-day attack reveal persistent federal vulnerabilities. The incidents echo past failures and raise fresh counterintelligence alarms.

Основное содержимое страницы с новостью.

Washington has absorbed another sharp reminder of its cybersecurity shortcomings. In the space of weeks, attackers compromised systems at the Pentagon and the FBI. The result: personal details on millions of service members, veterans, agents and applicants now sit in uncertain hands.

The Defense Department began notifying more than 2.8 million living individuals and roughly 294,000 deceased ones this week. Hackers had spent nine months inside a Defense Manpower Data Center network before detection. Ars Technica first connected the incidents.

Short. Direct. The records included Social Security numbers. Names. Addresses. Dates of birth. Race and sex. Most troubling, military occupational specialties. That last category lets foreign intelligence services map out who flies fighter jets, who maintains nuclear systems, who runs sensitive communications.

A notification letter shared on Reddit laid it out plainly. The breach began in October 2025. It lasted until July 2026. Officials discovered a vulnerability in a DMDC file-sharing system. They patched it immediately upon finding it. Yet the data had already moved.

The Pentagon says it sees no signs of misuse so far. That offers little comfort. Data like this doesn’t announce its arrival on the dark web or in a foreign ministry’s database. It simply appears when needed. And TechSpot reported the undetected access ran nearly nine months, exposing a combination of identifiers that goes beyond typical identity theft. TechSpot detailed the timeline.

But the FBI breach carries even sharper edges. Criminal hackers known as ShinyHunters claimed responsibility in September. They didn’t ask for money. They demanded the bureau retract a public advisory that described their extortion tactics. The group posted samples. Reuters examined a 5,000-line spreadsheet. It listed names, addresses, phone numbers, Social Security numbers. And assignments.

Some entries pointed to personnel in units handling China, Russia, cyber threats, surveillance and human intelligence. Reuters confirmed details by cross-checking against credit records and prior breach data. The hackers told the outlet they held far more. Two to three terabytes, they said. Reuters broke the exclusive on the intelligence roles.

The bureau declared it a major cybersecurity incident. Internal notices went to staff. Names, addresses, job titles, Social Security numbers. Later reports added medical records. Blood and urine tests. Psychiatric notes. The New York Times reviewed samples and called it one of the worst breaches of sensitive government information in years. It drew direct comparisons to the 2015 Office of Personnel Management hack that stole background files on 22 million people. That one was attributed to China. Officials swore it would never repeat. The New York Times examined the damage and fears for employees.

ShinyHunters gained entry through a zero-day flaw in Oracle PeopleSoft software. The same system many agencies and companies use for human resources. They moved laterally into Amazon-hosted government cloud storage. TechCrunch reported the group claimed access to HR, medical and criminal justice data. It also said the breach hit applicants as well as current and former employees. TechCrunch tracked the internal FBI declaration.

And the timing stings. The FBI had warned organizations about ShinyHunters months earlier. The group took offense. It struck back. CNN noted the hackers targeted the FBIJobs.gov portal. The site went offline. Investigators later confirmed the claims held weight. A Dutch arrest of an alleged associate added drama but few immediate answers. CNN covered the initial investigation and claims.

These aren’t isolated failures. The Pentagon breach lingered undetected for months. The FBI one exploited software that had known patches available. Both involved systems holding the most personal details about the people who protect the country. Occupational data. Unit assignments. Medical histories that could reveal vulnerabilities.

Experts have warned for years. Large agencies still run outdated infrastructure. Patching lags. Segmentation fails. Detection takes too long. The OPM breach a decade ago exposed fingerprints and clearance files. Congress held hearings. Money flowed into new systems. Yet here we are again.

POLITICO reported the FBI notified Congress that the incident qualified as major. It could harm national security or public safety. The bureau offered credit monitoring to affected Pentagon personnel. Twelve months through a private provider. Enrollment deadlines stretch into 2027. Small consolation for those whose details now circulate.

The Pentagon’s DMDC manages records for active duty, reserves, civilians, contractors, retirees. Over 60 million files. A single vulnerable file-sharing server became the entry point. No evidence the intruders came from a nation-state. But the data’s value to one is obvious. Occupational specialties paired with SSNs create targeting lists.

ShinyHunters has hit tech companies, retailers, financial firms before. This time the motivation looked like revenge. They posted a defaced screenshot of the FBI jobs site. Their logo. A message. Later they walked back some threats, calling it marketing. The data remains. Bleeping Computer detailed the PeopleSoft zero-day claim and the pivot to cloud storage. Bleeping Computer reported the technical vector.

So what happens next? Foreign services may buy subsets quietly. Criminal rings could launch spear-phishing campaigns tailored to specific agents. Blackmail becomes easier when you know someone’s medical history or family details. The uncertainty itself creates operational drag. Agents second-guess travel. Families change routines.

Congress will ask questions. Again. Agencies will promise reviews. Again. Yet the pattern persists. Complex legacy systems. Thousands of contractors. Slow adoption of modern controls. The two breaches, so close together, highlight how quickly small configuration mistakes cascade into national exposure.

Notifications continue. Affected individuals receive letters. Credit freezes are advised. But the real cost lies in eroded trust and heightened risk to personnel who operate in the shadows. Their names and roles no longer feel private. In intelligence work, that changes everything.

The government has spent billions on cybersecurity since the last major incidents. These events show the gap between spending and outcomes remains wide. Detection still arrives late. Response focuses on notification rather than prevention. And adversaries, whether criminals or states, keep finding the seams.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Pentagon breach exposed data on over 3 million people – media013.4129-09-2026
2Defense Department personnel data exposed in breach: Letter05.102-10-2026
3Stolen FBI data reveals employees’ roles in intelligence and surveillance07.7924-09-2026
4Letter: Defense Department personnel data exposed in breach05.6228-09-2026
5ShinyHunters FBI Data Breach: Leaked Spreadsheet Names Staff in China, Russia and HUMINT Roles06.5824-09-2026
6Хакеры похитили данные 3 млн сотрудников Пентагона012.2429-09-2026
7Defense Department personnel data exposed in breach: Letter05.128-09-2026
8Defense Department personnel data exposed in breach: Letter05.128-09-2026
9Не секретные материалы: ФБР не знает, как хакеры похитили данные агентов07.5329-09-2026
10Группировка ShinyHunters заявляет, что взломала ФБР и похитила данные всех сотрудников09.5723-09-2026

Классификация: Армия и ОПК. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 11.89. Источник: www.webpronews.com.