Count (new): A Defense Department / Department of War official told CNN (story updated Sep 28, 2026) the breach hits 2.76 million living individuals and 294,000 deceased. ABC News (Sep 28) and SecurityWeek (Sep 29) match that official tally. Earlier Military Times reporting (Sep 24) had only anonymous “~4 million may be affected” sourcing — retire that as the headline figure; keep it as context that unofficial estimates ran high of the confirmed living count.
Window and data: Victim letters dated mid-September (Military Times / CNN) say a security vulnerability in a DMDC file-sharing system was discovered July 16, 2026, patched the same day, and that analysis found unauthorized access between October 2025 and discovery. Exposed records varied by person and included SSNs alongside names, dates of birth, contact details, demographic data, and — in some cases — military occupational specialties. The letter does not name the file-sharing product or CVE. DoW says it has no indications of misuse and is offering one year of IDX credit monitoring / identity restoration.
Scale context: DMDC held at least 60 million records as of FY2024 (DMDC site / CNN) covering military and civilian personnel, contractors, family members, retirees and veterans. Actor remains Undisclosed — no known cybercrime group has claimed a DMDC hit in public reporting tied to this incident.
POV: Confirmed multi-million SSNs plus MOS is a counterintelligence story first, identity-theft second. Pairing job specialty with identifiers is useful for foreign intel and targeted phishing even if no misuse is claimed yet. Action for affected cohorts: take the IDX offer, freeze credit, treat MOS + contact data as already in hostile hands until proven otherwise. Watch for a named product/CVE and any IC attribution.
