Between October 2025 and mid-July 2026, unauthorised users had access to a file-sharing system run by the Defense Manpower Data Center (DMDC), the Pentagon office that keeps personnel records for military and civilian staff. According to TechCrunch, the files were stored unencrypted.
The Department of Defense says the breach affects about 2.8 million living people and roughly 300,000 who have died, more than 3 million in total, according to Federal News Network. Exposed data includes Social Security numbers, names, dates of birth, contact details and military service information. Notification letters say DMDC found the problem on 16 July, patched the system and restored it. The notice first became public when a recipient shared it on Reddit.
The reporting leaves out some things that matter:
Those gaps will probably fill in over the coming weeks. The pattern is already visible.
1. A bug opened the door. File-sharing and file-transfer systems are a favourite target because they sit on the edge of the network and hold other people's data. Patching one is necessary, but it only closes the entrance the attackers used.
2. The records were unencrypted at rest. Once someone is inside, encryption is the layer that decides whether they walk away with readable Social Security numbers or with unusable files. Whether encryption would have helped here depends on where the keys lived, but leaving it out removes the option.
3. Nine months went by before anyone noticed. Access began in October 2025 and was found in July 2026. A system that holds records on tens of millions of people should generate an alarm when a few million of them are read by an account that doesn't normally read them.
A file share full of sensitive records is an old problem. What's new is that the same records now flow into AI tools. HR teams paste employee lists into a chat window to draft letters. Analysts upload spreadsheets of customer identifiers to get a summary. Each prompt or upload copies sensitive data into a new place, usually with no retention rule and no log that anyone reads.
That is the same failure on a smaller scale: more copies of regulated data, in more locations, held by systems nobody inventoried. The record that sat unencrypted on the file share and the record pasted into a prompt have the same risk, and neither shows up in the places a security team looks first.
Governance AI covers the last point on that list. It sits between your people, or your agents, and the model providers. Guardrails check prompts and outputs against the policy you set, so a Social Security number or a customer identifier can be flagged, redacted or blocked before it leaves for a model. Every decision is written to an audit trail, so when a regulator or a customer asks what was sent where, you have an answer.
It does not secure a file-sharing server, and it would not have stopped this breach. That belongs to your patching, encryption and monitoring. What it does is stop the AI tools your staff already use from becoming a second, unlogged copy of the data you are trying to protect.
Explore Governance AI or talk to us about setting data-handling rules on every prompt before sensitive records leave your control.
Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.
See how it works →