The seal of the U.S. Department of Defense appears on the screen of a smartphone placed on a reflective surface onto which the U.S. flag is projected. —Samuel Boivin—NurPhoto/Getty ImagesA reported monthslong breach in the Defense Department’s human resources database exposed personal information of millions of military personnel and those related to them, including their Social Security numbers and job details.Unidentified Pentagon officials confirmed to CNN and ABC News that some 2.76 million “living individuals” and 294,000 “deceased individuals” have been affected by the breach at the Defense Manpower Data Center (DMDC). The breach was first reported by defense-focused news publication Military Times on Thursday, citing a breach notification letter to a person whose information was in the affected files.It remains unclear what particular files were accessed and who was behind the incident. TIME has requested comment from the Pentagon. The length of the breach and the amount of personal information exposed present a security risk for many personnel linked with the department, and some experts say it makes other security compromises, like phishing attempts, easier for bad actors.What we know about the breachThe DMDC collates personnel, manpower, training, financial, and other data for the Defense Department for healthcare, retirement funding, and other administrative needs. Its website says that based on FY2024 data, it has the records of more than 60 million people—including the military, civilians, contractors, family members, retirees, and veterans.But the Military Times reviewed a Sept. 18 letter from the DMDC notifying its recipient of a data breach. The letter reportedly said it discovered on July 16 a security vulnerability in the center’s file-sharing system. The notice reportedly details that between October 2025 and the time of discovery, some “unauthorized users” accessed files on a server containing the personal information. The type of personal information varies from names to dates of birth, contact information, and others.DMDC then said it updated the file-sharing system to address the vulnerability. The letter reportedly added that there has been no indication of misuse of the recipient’s information.Not the first hackThe latest incident involving Pentagon data emerged as the FBI confirmed it was looking into criminal hacking group ShinyHunters’s apparent attack on its jobs website. The group claimed to have stolen “very sensitive data” on nearly all agents and job applicants in response to an FBI notice about them issued in May. (ShinyHunters were also behind a high-profile hack in May of education platform Canvas.)It’s still unclear how massive the previous FBI breach was, but a New York Times analysis found that it may have involved the stealing of home addresses, Social Security numbers, and job assignments, on top of other personally identifiable information. Reuters reported last week that the hackers claimed they have obtained about 2-3 terabytes of data. Some of the data Reuters reviewed also revealed details of assignments to specific field offices, as well as FBI units engaged in high-stakes intelligence, security, or counterespionage work, which risks endangering national security. In a statement to 404 Media and the Times, the FBI said it was “working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted—including multiple bureau-wide communications within 24 hours of public reporting.”The FBI incident also follows a breach that may have exposed more than 153 million driver’s licenses in the U.S. and Canada.What affected personnel can doSecurity experts have previously warned that access to troves of records poses a massive security risk, especially if these fall into the hands of foreign actors. Justin Sherman, a senior associate at the Center for Strategic and International Studies, wrote about the license data breach earlier this month: “It can be tempting to dismiss the next hack of a database as ‘just another data breach.’... But breaches do not exist in a vacuum.”The DMDC said in its notice to affected personnel that it was offering year-long credit monitoring and identity-restoration services through IDX, a private firm contracted by the department.According to the Federal Trade Commission, anyone could place a free credit freeze with each of the three major credit bureaus—Equifax, Experian, and TransUnion.Active duty personnel and National Guard members could also get free electronic credit monitoring to spot problems that could stem from identity theft.