Federal Data Breaches Expose Millions of Personnel Records

AI-generated image · Bay Street Wire
A monthslong compromise of a Pentagon network and a separate FBI hack have leaked sensitive data on military and intelligence employees.
The U.S. government is facing a critical security crisis following two major data breaches in a single month. According to Ars Technica, the Pentagon is notifying over 2 million current and former military members that their personnel records were stolen. The breach targeted a system operated by the Defense Manpower Data Center, which manages more than 60 million records for veterans, retirees, contractors, civilians, and military personnel.
Ars Technica reports that the stolen data includes names, addresses, sex, race, Social Security numbers, and occupational specialties. The latter is noted as particularly dangerous, as it could allow foreign intelligence agencies to identify high-value military targets. The Pentagon stated that 2.8 million living individuals were affected, though officials have not disclosed how the breach occurred or if ransom demands were made.
This follows a separate incident reported by Ars Technica, citing Reuters, in which the ransomware group ShinyHunters claimed to have breached FBI systems. The group stole records of thousands of current or former FBI employees, including those with job titles tied to investigations involving Russia or China. While ShinyHunters claims it will not release the data, Ars Technica notes that the group's security is likely insufficient to stop nation-state hackers.
In response to the FBI breach, FBI Cyber Division Assistant Director Brett Leatherman called for ShinyHunters members to surrender, following the arrest of one member by Dutch police. Together, these incidents are described by Ars Technica as one of the most significant potential espionage hauls since the 2015 Office of Personnel Management hack, where Chinese state hackers stole 22.1 million records.

