Hackers stole millions of US military personnel records during months-long data breach
Hackers stole millions of US military personnel records during months-long data breach
黑客在长达数月的网络攻击中窃取了数百万份美国军方人员记录
The U.S. government is reportedly alerting millions of current and former U.S. military service members and staff that their personal information was stolen during a months-long breach of the Pentagon’s personnel records, the latest in a spate of thefts involving federal workers’ data in recent months. 据报道,美国政府正在通知数百万现役和退役的美国军人及工作人员,他们的个人信息在五角大楼人事记录长达数月的泄露事件中被窃取。这是近几个月来一系列涉及联邦雇员数据被盗事件中的最新一起。
A data breach notification from the Defense Manpower Data Center (DMDC) shared on Reddit says that several unauthorized users exploited a security vulnerability in an unspecified file-sharing system over several months between October 2025 and mid-July 2026. The breach exposed personally identifiable information, including Social Security numbers, alongside a person’s name, date of birth, sex, race, and other information about their military service. The notice says that the personnel records were unencrypted. 一份在 Reddit 上分享的国防人力数据中心(DMDC)数据泄露通知显示,几名未经授权的用户在 2025 年 10 月至 2026 年 7 月中旬期间,利用了一个未指明的文件共享系统中的安全漏洞。此次泄露事件暴露了个人身份信息,包括社会安全号码,以及个人的姓名、出生日期、性别、种族和其他关于其服役情况的信息。通知称,这些人事记录并未加密。
According to CNN and Federal News Network, a Pentagon official said the breach affects about 2.8 million living people, and close to 300,000 people who are deceased. The U.S. military has 1.3 million active service members as of March. 据美国有线电视新闻网(CNN)和联邦新闻网(Federal News Network)报道,一位五角大楼官员表示,此次泄露事件影响了约 280 万在世人员和近 30 万已故人员。截至 3 月,美国军队共有 130 万现役军人。
The DMDC may not be widely known to the general public, but serves as one of the Department of Defense’s records-keeping units. The DMDC maintains over 60 million records for U.S. military and civilian staff and their family members to help determine benefits and entitlements, such as healthcare and retirement. The unit also provides a critical service as the military’s “leading identity management provider,” which links active service members, employees, and contractors to credentials, such as smart cards and passwords. These are used to access Pentagon computer systems, buildings, and bases. DMDC 对公众来说可能并不广为人知,但它是国防部的记录保存单位之一。DMDC 维护着超过 6000 万份美国军方和文职人员及其家属的记录,以帮助确定医疗保健和退休等福利和权益。该单位还作为军方“领先的身份管理提供商”提供关键服务,将现役军人、雇员和承包商与智能卡和密码等凭证关联起来。这些凭证用于访问五角大楼的计算机系统、建筑物和基地。
“We make sure that the right people get access and the wrong people don’t: security of identity information is paramount,” the DMDC’s website reads. The Department of Defense, which oversees the DMDC, said it does not have any indication that the information was misused, but did not say how it reached that conclusion. TechCrunch contacted a Pentagon spokesperson to ask if officials had any communications from the hackers, whose identities are not known, but we did not hear back. DMDC 网站上写道:“我们确保正确的人获得访问权限,而错误的人无法获得:身份信息的安全至关重要。”负责监管 DMDC 的国防部表示,目前没有任何迹象表明这些信息被滥用,但并未说明得出该结论的依据。TechCrunch 联系了五角大楼发言人,询问官员是否收到过黑客(身份不明)的任何通讯,但未得到回复。
This is the latest major breach of federal workers’ personal information in recent months, following a recent breach at the FBI earlier in September attributed to the ShinyHunters hacking group. The hackers told TechCrunch that they had taken the personal information of most of the FBI’s agents and staffers, including applicants. The breach has been billed as a “counterintelligence disaster” amid the risks that a foreign government could obtain and use the information to profile, target, or coerce federal workers into handing over sensitive information. The ShinyHunters hackers have said that they will not publicly release the stolen FBI data. 这是近几个月来联邦雇员个人信息遭受的最新一起重大泄露事件,此前 9 月初联邦调查局(FBI)也发生了类似事件,该事件被归咎于 ShinyHunters 黑客组织。黑客告诉 TechCrunch,他们已经获取了大多数 FBI 特工和工作人员(包括申请人)的个人信息。此次泄露事件被视为一场“反间谍灾难”,因为外国政府可能获取并利用这些信息对联邦雇员进行画像、锁定目标或胁迫其交出敏感信息。ShinyHunters 黑客表示,他们不会公开泄露的 FBI 数据。
Both breaches involving the FBI and the DMDC mirror similar thefts of government personnel records in the past. In 2015, a breach of the U.S. government’s human resources department, known as the Office of Personnel Management, was broadly attributed to China. The theft allowed the hackers to steal the private records of more than 22 million U.S. government employees, many of whom had security clearances. 涉及 FBI 和 DMDC 的这两起泄露事件与过去发生的政府人事记录被盗事件如出一辙。2015 年,美国政府人力资源部门——人事管理局(Office of Personnel Management)发生了一起泄露事件,该事件被广泛归咎于中国。那次窃取事件使黑客得以盗取超过 2200 万名美国政府雇员的私人记录,其中许多人拥有安全许可。
Did you receive a notice about this data breach? We want to hear from you. You can contact this reporter securely on Signal at zackwhittaker.1337, or reach him by email at zack.whittaker@techcrunch.com. 您是否收到了关于此次数据泄露的通知?我们希望听听您的反馈。您可以通过 Signal(账号:zackwhittaker.1337)安全地联系本报道记者,或通过电子邮件 zack.whittaker@techcrunch.com 与他联系。