← All posts

The Pentagon’s Personnel Database Sat Unencrypted for Months. What Is Sitting Unprotected in Yours?

Last week the Defense Department began telling roughly three million people that their Social Security numbers and other personal details had been accessible to unauthorized users for about nine months. According to reporting on the notification letters, the exposure ran from October 2025 until mid-July 2026, when the problem was finally discovered. The data sat on a server that was not encrypted.

If you run a company, you may be tempted to file this under “government problem.” Don’t. The failure here is not exotic. It is the same failure that shows up in boardrooms every quarter, and it is one you can check on this week.

What was reported

The Defense Manpower Data Center (DMDC) is the Pentagon unit that maintains identity and personnel records, more than 60 million of them. According to the Department’s notification, a vulnerability in a DMDC file-sharing system allowed unauthorized users to access files. Time reported about 2.76 million living individuals and about 294,000 deceased individuals were affected. The exposed information included names, dates of birth, contact information, and Social Security numbers, along with job details such as military occupational specialty.

The Department says it has seen no indication the information was misused, patched the vulnerability, and is offering a year of credit monitoring through IDX. Notification letters reportedly went out on September 18, and the story became public on September 24. Those are official statements, and reporters have not seen an explanation of how the “no indication of misuse” conclusion was reached. Who the unauthorized users were has not been publicly identified.

Three lessons that travel to the boardroom

First, “no evidence of misuse” is not “no misuse.” Absence of evidence is only reassuring if you had the logging and monitoring to see evidence in the first place. A system that went roughly nine months without anyone noticing unauthorized access is, by definition, a system where detection was weak. In Cyber Risk Is Business Risk, the Three Questions framework starts with a simple one: how would we know? If an attacker were inside your most sensitive file-sharing platform today, what specific control would tell you, and how fast?

Second, encryption is a business decision, not a technical footnote. Reporters describe the records as unencrypted. Encryption does not stop every breach, but it changes what a breach is worth to an attacker and what it costs you afterward. Boards rarely ask whether their most sensitive data stores are encrypted at rest, because the answer sounds like a detail. It is not. It is one of the cheapest ways to turn a catastrophe into an incident.

Third, file-sharing systems are a favorite blind spot. These tools exist to move data around easily, which is exactly why they accumulate sensitive material over time and why they are attractive targets. They often sit outside the inventory that security teams actively watch. The question is not whether you use one. It is whether anyone can tell you what is in it.

Compliance is not the same as security

Federal agencies operate under extensive security frameworks and audit regimes. Having paperwork is not the same as having protection, and this incident is a reminder that a checked box on a compliance report says little about whether a particular server was encrypted or watched. I make this argument throughout the book: compliance tells you that you met a minimum standard on a given day. Security tells you whether the data in front of an attacker is actually safe today. Your board needs to hear about both, and it should never accept the first as a substitute for the second.

The cost does not stay with the victim organization

Nearly three million people now have to watch their credit, freeze files, and stay alert for fraud tied to a Social Security number they cannot change. In a corporate setting, that downstream burden turns into notification costs, litigation, regulatory attention, and lost trust. It also raises the personal liability question for executives and directors who were warned about a gap and did not act. Directors are expected to show they asked reasonable questions and followed up.

What to ask your CISO this week

  1. Where is our most sensitive personal data stored, and is it encrypted at rest? Ask for a yes or no for each major system, not a general reassurance.
  2. Which file-sharing and transfer tools are in use, including the ones teams adopted on their own? Ask who owns each one and what sensitive data it holds.
  3. If someone accessed those systems without permission, how long would it take us to find out? Ask for the actual detection time from the last test, not the target.
  4. When we say “no evidence of misuse,” what monitoring supports that statement? Make sure your incident communications rest on what you can actually see.
  5. Who decides, and how fast, when we must notify customers or regulators? Gaps between discovery and notification draw scrutiny of their own.

The bottom line

The Pentagon’s problem is not that it was targeted. Every organization with valuable data is targeted. The problem is the combination of unencrypted sensitive data, a vulnerable file-sharing system, and a long stretch before anyone noticed. Your board cannot fix a vulnerability, but it can insist that these questions get asked and answered with evidence. Start this week.