The Pentagon is telling more than 2 million current and former members of the military that personnel records holding sensitive personal information were stolen during a monthslong compromise of one of its networks, Ars Technica reported on Thursday.
The records, according to one notification letter posted to Reddit, included Social Security numbers, names, addresses, sex, race and occupational specialty. That last category could be especially valuable to foreign adversaries, the site reported, because it could help their intelligence agencies identify high-value military personnel.
Starting last October, the hackers gained access to a system operated by the Defense Manpower Data Center, which compiles the Defense Department’s personnel records. The Pentagon says the breach compromised the records of 2.8 million living people.
It is the second major network breach in recent months to expose sensitive United States government personnel records that criminal groups or foreign adversaries could put to use. Last month the ransomware group ShinyHunters claimed it had hacked into F.B.I. systems and stolen records on thousands of the agency’s current and former employees. Reuters reported that the job titles in those records included ones related to investigating China or Russia.
ShinyHunters has said it has no plans to release the information. But the promises of a criminal organization that has hacked and extorted hundreds of organizations mean very little, Ars Technica reported, and the group’s own defenses are unlikely to hold up against nation-state intelligence hackers. An F.B.I. official this week called on members of the group to turn themselves in.

