Pentagon Agency Exposes 3 Million Records on Unencrypted File-Sharing Server for Nine Months
The Defense Manpower Data Center left a file-sharing server containing unencrypted PII accessible to unauthorized users for approximately nine months, exposing Social Security numbers, dates of birth, and other sensitive details for nearly 3 million individuals. The dual failures of storing sensitive data in plaintext and allowing unauthorized access to persist undetected for such an extended period represent fundamental breakdowns in both data protection and monitoring practices. The sensitivity of this data — tied to military personnel and their families — makes it a high-value target for foreign adversaries and identity thieves alike. This breach underscores that government agencies handling sensitive national security data must enforce encryption at rest as a non-negotiable baseline control, and that prolonged unauthorized access without detection signals a critical gap in continuous monitoring capabilities.
Tactical Insight
Immediate actions
- Encrypt all stored PII and sensitive data at rest using AES-256 or equivalent standards, regardless of the server's perceived internal accessibility.
- Audit all file-sharing servers and internet-facing systems immediately to identify unauthorized access or misconfigured permissions.
- Revoke and re-issue credentials for all accounts with access to affected systems pending a full investigation.
Long-term improvements
- Implement a formal Data Classification Policy that mandates encryption and strict access controls for any system storing PII or regulated data.
- Enforce the principle of least privilege by conducting quarterly access reviews to ensure only authorized personnel can reach sensitive file repositories.
- Establish a comprehensive Data Loss Prevention (DLP) program to detect and block unauthorized exfiltration of sensitive files.
Detection measures
- Deploy a Security Information and Event Management (SIEM) solution with alerting rules tuned to flag anomalous access patterns on file-sharing servers in real time.
- Implement User and Entity Behavior Analytics (UEBA) to detect unusual login times, volumes, or geographic anomalies on systems containing sensitive data.
- Set a maximum threshold for unresolved security alerts — nine months of undetected access is unacceptable and should trigger mandatory escalation procedures.