Military Data Removal: What to Do After the Pentagon Breach

By Thomas Daly, founder and CEO, Priwall by mePrism


Active-duty and retired military personnel should remove personal information from commercial data brokers now, alongside following official breach-response instructions. The purpose is to reduce the additional information an adversary could connect to exposed military records, not to erase the breach itself. Priwall by mePrism offers a way to handle broker-removal requests and ongoing monitoring rather than managing each request yourself (Priwall by mePrism).

On September 25, 2026, CNN reported that a breach at the Defense Manpower Data Center exposed Social Security numbers and other personal information belonging to current and former military personnel, including occupational specialties in some cases (CNN). The immediate question for military families is what they can do next.

The answer should include credit protection and a review of the personal information still available for sale. Treat those as complementary precautions, not competing choices.

What happened in the Pentagon personnel data breach?

According to a notification letter reviewed by CNN, unauthorized access to a vulnerable DMDC server began in October 2025, and the Pentagon discovered and remediated the issue in July 2026 (CNN). CNN cited reporting that four million Defense Department personnel could be affected, but said the total number impacted remained unclear (CNN).

The Pentagon reported no indication of misuse at the time, and the identity of those responsible was unclear (CNN). Those limits matter: a serious response does not require claiming that foreign intelligence services already possess or have exploited this particular dataset.

Nor does the reporting establish that a commercial data broker caused the breach (CNN). The connection is what could happen afterward: information taken from DMDC could be combined with commercial datasets to reveal more about defense personnel’s earnings, debts, relationships, spending habits, and other aspects of their lives (CNN).

Why military data removal is a national-security issue

An exposed military record and a commercially available personal profile are different sources of risk. Together, they could help someone identify a service member’s role, understand personal circumstances, and construct a more persuasive approach for phishing, impersonation, or coercion (CNN; U.S. Naval Institute).


This threat was documented years before the latest breach. In November 2023, Duke University published “Data Brokers and the Sale of Data on U.S. Military Personnel,” research sponsored by the United States Military Academy at West Point under a cooperative agreement (Duke University).


Researchers purchased sensitive, individually identified information about active-duty personnel, veterans, and their families for as little as 12 cents per record, including health, financial, and religious-practice information (Duke University). They tested purchases through both U.S.-oriented and “.asia” domains and found inconsistent customer-verification practices, including in transactions involving buyers outside the United States (Duke University).

The December 2022 U.S. Naval Institute Proceedings article “Data Brokers Are a Threat to National Security” had already described how commercial data could support tracking, impersonation, bribery, and blackmail of military personnel (U.S. Naval Institute). Federal policy subsequently addressed the broader danger: the Justice Department’s Data Security Program, effective April 8, 2025, restricts or prohibits specified transactions that could give countries of concern access to U.S. government-related data and Americans’ bulk sensitive personal data (Department of Justice).


The public record is clear that this is a longstanding national-security concern, not a new theory prompted by one headline. Our recommendation is to act on that knowledge at the individual and organizational level.

Why retired military personnel and families should act, too

The Duke research explicitly included veterans and military families, not only people currently serving (Duke University). Its warning covered potential profiling, blackmail, information campaigns, and other targeting of service members, veterans, families, and acquaintances (Duke University).


If you have retired, do not use your current employment status as a reason to dismiss personal-data exposure. Review what someone could learn about you and your household, and encourage adult family members to review their own exposure as well.


mePrism has repeatedly covered this problem, from “How Data Brokers Threaten National Security—and Put Government Personnel at Risk” to “Your Data is a Weapon: The Open Secret Threatening National Security.” We revisited the military-specific evidence in “The West Point Warning: Why Personal Data is a National Security Liability.”


Our position remains that protecting people requires attention to information outside the systems their employers control. After a breach, that work deserves greater urgency.

What to do now: protect your credit and reduce broker exposure

Start with the official notification and instructions that apply to you. Then separate the work into financial protection, commercial-data removal, and ongoing follow-up.

  • Protect against new-account fraud: Consider freezing your credit with each of the three nationwide credit bureaus, Equifax, Experian, and TransUnion; a freeze is free and makes it harder for someone to open new credit in your name (FTC credit guidance).

  • Watch for financial misuse: Review credit reports and account statements, and take advantage of legitimate monitoring offered after the breach (FTC breach guidance; FTC credit guidance).

  • Start personal-data removal: Identify broker and people-search listings exposing your information, then request removal directly or use a service that manages the process (Priwall by mePrism).

  • Keep checking: Make follow-up part of the process because broker records can reappear after removal (Priwall by mePrism).


A useful test is to ask what each action actually addresses. A credit freeze limits access to your credit report for new-credit decisions; it is not a data-broker opt-out (FTC credit guidance). Broker removal addresses information available through covered commercial sites; it is not a substitute for a credit freeze, monitoring, or official military security instructions.

How Priwall by mePrism fits into the response

Priwall by mePrism is a personal-data removal service that finds exposed information, manages removal workflows across covered data-broker and people-search sites, and provides ongoing monitoring and reporting (Priwall by mePrism). For someone who does not want to manage individual opt-outs and repeated checks, it offers a way to make that work an ongoing process (Priwall by mePrism).

When choosing a removal service, look for evidence of removal outcomes, not just the number of requests submitted. Sensiba LLP independently recalculated Priwall by mePrism’s reported removal-rate figures under an AICPA AT-C Section 215 agreed-upon procedures engagement (signed practitioner report). Across a representative sample of Priwall’s enterprise customers, the recalculation showed greater than 92% confirmed removal at 30 days and greater than 99% at 90 days, with a four-day median time to first confirmed removal (report findings). These findings concern the measured enterprise population, not military-specific outcomes or protection against espionage; they should not be treated as a guarantee of future results (report scope).

The objective is to reduce continuing commercial exposure. No removal service should promise to retrieve stolen DMDC records, delete every copy already held by an attacker, or eliminate the possibility of surveillance and targeting.


For active-duty personnel and military retirees, now is the right time to begin that work. Explore Priwall by mePrism to start addressing the broker-held information that could add context to exposed records.

You cannot control every copy of information that has already escaped. You can take action to reduce what remains readily available to supplement it.

Common questions about military data removal

No. Broker removal addresses continuing commercial exposure; it cannot recover stolen records or guarantee deletion of copies already held by another party. Use it alongside the official breach response, not instead of it.

We recommend that military retirees review their exposure and begin removal just as active-duty personnel should. The underlying research includes veterans and their families, so the concern does not apply only to people currently serving (Duke University).

No. Credit monitoring helps flag changes to a credit report, while broker removal addresses personal information available through covered commercial sites (FTC credit guidance; Priwall by mePrism). They serve different purposes and should not be treated as interchangeable.

Yes. You can make individual opt-out requests and check for reappearing listings yourself, or use a service such as Priwall by mePrism to manage removal workflows and ongoing monitoring. The important decision is how you will sustain the work, not simply whether you submit the first request.

Ready to try Priwall by mePrism yourself?

If you are an individual executive evaluating personal coverage outside an employer-funded program, you can start with a free exposure scan.

Sign up for Priwall by mePrism coverage.

Tom Daly is the founder and CEO of Priwall by mePrism, the enterprise open-source data-removal platform used by security, executive-protection, and digital-risk teams to shrink broker exposure across hundreds of U.S. data brokers. He writes on data privacy, cybersecurity, and constitutional privacy at the Priwall blog and on LinkedIn.

Next
Next

Independent verification of data-removal efficacy: Priwall by mePrism's AICPA AT-C 215 practitioner report