Last Updated: September 30, 2026 Reading Time: 9 min
If you got a letter from the Defense Manpower Data Center in the last two weeks, or you ever applied for an FBI job, you are probably reading headlines that say "3 million," "4 million," or "Pentagon hacked." Most of that coverage blends two different incidents and states press estimates as facts. This post separates what a government document confirms from what a reporter was told, and then gives you the six things to do in the next 72 hours, each with the law behind it.
What Is Confirmed, What Is Reported, and What Nobody Has Said
I sorted every fact in circulation into three buckets. "Confirmed" means a government document or official page says it. "Reported" means a named outlet says it, usually from a letter or a memo the outlet obtained. "Unknown" means nobody has said it at all.
| Question | DMDC incident | FBI jobs-portal incident | Status |
|---|---|---|---|
| Are these the same event? | File-sharing system at the Defense Manpower Data Center | Oracle PeopleSoft database behind FBIJobs.gov | Reported as separate; no document connects them |
| How many people? | About 2.76 million living and about 294,000 deceased, per a Pentagon official quoted by TIME on September 29; an earlier press estimate said "up to 4 million" | Not stated by anyone | Reported; the two DMDC figures conflict, and neither appears in a published document |
| What data? | Social Security numbers plus at least one other identifier (date of birth, address), per the letter as described by Military Times | SSNs, dates of birth, addresses, per press accounts | Reported |
| When? | Unauthorized access reportedly ran from October 2025 to July 16, 2026; letters dated September 18, 2026 | Surfaced publicly September 23; an internal FBI memo reportedly dated September 25 or 26 | Reported |
| Was it malicious? | The Pentagon reportedly said on September 3 there was no indication of malicious intent; the letter reportedly says no indication of misuse | Attributed in press to a criminal group | Reported, and the two incidents are characterized differently |
| Is there an official notice? | None on dwp.dmdc.osd.mil as of September 30 | None from the FBI or DOJ | Confirmed absent (we checked the DMDC portal ourselves) |
| What are victims offered? | 12 months of credit monitoring through IDX, enrollment through the IDX DMDC response page; no deadline, no insurance amount, no restoration service listed on the response page | Nothing identified | Confirmed for DMDC (the IDX response page); Unknown for FBI |
| Did the agencies notify Congress under the 7-day major-incident rule? | Not stated | Not stated | Unknown |
| Are veterans' records in the DMDC set? | DMDC holds veteran and dependent records, and press lists retirees among affected groups, but no document states a veteran share | Not applicable | Unknown |
Two things follow from that table. First, do not repeat a headcount as if it were settled. The 2.76 million figure came from an unnamed official; the 4 million figure came from a reporter's estimate that the same outlet labeled unconfirmed. Second, the absence of an official page matters for your safety, not just for the record: there is no government site you can check a letter against, which is exactly the gap a phishing campaign will exploit.
The 72-Hour Checklist, in Order
Every action below is free, and every one is backed by a statute or an official page, not by a vendor's suggestion.
Hour 1: Freeze your credit at all three bureaus
A security freeze blocks new accounts from being opened in your name. Under 15 U.S.C. 1681c-1(i)(2)(A), a credit bureau must place a freeze free of charge on your direct request, within one business day if you ask electronically or by phone (three business days by mail). Removal is even faster: when you ask by phone or through the bureau's secure site, the bureau has one hour to lift it.
You have to do this separately at Equifax, Experian, and TransUnion. The freeze does not affect your credit score, and the Federal Trade Commission's guidance confirms it is free to place and free to lift. If you are about to apply for a mortgage or a car loan, lift it for that lender and refreeze afterward.
Hour 2: Get an IRS Identity Protection PIN
Tax-refund fraud is the most common way a stolen Social Security number gets turned into money, and the IP PIN is the only free control that actually blocks it. The PIN is a six-digit number that stops anyone else from filing a federal return under your SSN. You do not have to be a breach victim to qualify; anyone who can verify their identity through an IRS online account can opt in. The PIN is valid for one calendar year and the IRS issues a new one each year.
Hour 3: Enroll in the IDX offer through the DMDC response page
DoD's contracted vendor, IDX, is offering DMDC letter recipients 12 months of credit monitoring at no cost. Enroll through IDX's DMDC response page. Do not wait for a deadline announcement, because as of September 30 the response page publishes none. It also publishes no identity-theft insurance amount and no restoration service. If your letter promises more than the page shows, keep the letter.
If you applied for an FBI job and never got a letter, there is no offer to enroll in yet. Your protection is steps one and two.
If you will not freeze: place an initial fraud alert
A freeze is better, but a fraud alert is the fallback. You contact one bureau and it must notify the other two. An initial alert lasts at least one year from the request. Later, if you file an identity-theft report, an extended alert lasts seven years. A fraud alert only tells lenders to verify your identity; it does not block the account the way a freeze does.
Lock down the accounts that pay you
Turn on two-step verification and account alerts everywhere your federal money lives: your Thrift Savings Plan account, myPay or your payroll provider, OPM Services Online if you are an annuitant, milConnect if you are a service member or retiree, and Login.gov, which fronts many of them. I am keeping this generic on purpose: the TSP and Social Security pages were not reachable when I checked, so I will not quote their specific settings. Log in and look for "security" or "alerts."
Save the letter
Your DMDC letter is evidence, so keep it. If someone later opens an account in your name, an identity-theft report (the FTC report or a police report) plus proof of your identity is what unlocks the seven-year extended fraud alert under 15 U.S.C. 1681c-1(b); the breach letter is supporting documentation a bureau may ask for when you dispute the account.
What the 2015 OPM Breach Victims Got, and What You Get
Congress wrote the 2015 remedy into law. The 2026 offer has no statute behind it, and the two sit side by side below.
After the 2015 OPM breaches, Congress wrote the remedy into law. Section 633(a) of the Consolidated Appropriations Act, 2017 (Public Law 115-31) required OPM, for fiscal years 2016 through 2026, to provide every affected individual complimentary identity protection that is "effective for a period of not less than 10 years" and "includes not less than $5,000,000 in identity theft insurance." That mandate ends with fiscal year 2026, which closed September 30, 2026. We covered the wind-down in our guide to the OPM breach coverage expiring in September 2026, and a pending bill, the RECOVER PII Act (S. 5217), would amend section 633 to extend coverage for people whose information was compromised in federal breaches. Its text is on govinfo; its prospects are not something I can verify, so I will not handicap them. Our RECOVER PII Act explainer tracks it.
| Entitlement | 2015 OPM breach victims | 2026 DMDC letter recipients | 2026 FBI applicants |
|---|---|---|---|
| Legal basis for coverage | Pub. L. 115-31, section 633(a) | None identified; an agency-contracted offer | None identified |
| Years of identity protection | At least 10, by statute | 12 months, per the IDX response page | Not established |
| Identity-theft insurance | At least $5 million, by statute | Not stated on the response page | Not established |
| Enrollment deadline | Tied to the original notices | None published | Not established |
| Status today | Statutory mandate ended September 30, 2026 | Opening now | No program identified |
| Free credit freeze | Yes, 15 U.S.C. 1681c-1 | Yes, same statute | Yes, same statute |
FedTools 2026 comparison. Statutory cells are quoted from Public Law 115-31; the DMDC cells are read from the IDX response page on September 30, 2026; "not established" means no document or official page states it.
The statutory floor Congress set in 2017 was ten years and five million dollars. The 2026 offer, made under no statute, is one year and no stated insurance, and it landed the same week the 2015 mandate switched off. Do not assume the new offer replaces the old program; they are different programs for different people.
The Phishing Wave Is the Next Problem
Because DMDC's public portal shows no notice, a letter recipient has nothing official to compare against. That is a gift to scammers. Three rules:
- DMDC, DoD, IDX, and the FBI will not email or call you to collect a Social Security number. Enrollment runs through IDX's DMDC response page, not through an inbound call or email.
- Verify the IDX phone number against your own letter, not against a news article or a search result.
- Anyone who contacts you "about the breach" and asks you to confirm your SSN, your date of birth, or a bank account is the breach, not the remedy.
Can You Sue?
The Privacy Act allows a suit against the government, but the bar is high. Under 5 U.S.C. 552a(g)(4), you must show the agency acted intentionally or willfully, and recovery is actual damages with a $1,000 statutory floor, plus costs and fees. Under 552a(g)(5), the claim must generally be filed within two years of when it arose; if the agency materially and willfully misrepresented information, the clock runs from your discovery of the misrepresentation. The DMDC letter reportedly says there is no indication of misuse, which cuts against both damages and willfulness. Talk to a lawyer before you assume a per-person payout.
For the record-keeping side: OMB's FISMA guidance (M-25-04) treats unauthorized access to the personal information of 100,000 or more people as a major incident, and federal law requires agencies to notify the relevant congressional committees within seven days of determining that a major incident occurred. Whether either agency made that notification is not public. I am not asserting that they did or did not.
What Is Still Unknown
- Whether DMDC or the FBI will publish an official notice, and when.
- The FBI headcount, and whether FBI applicants will be offered anything.
- Whether the "no indication of misuse" language in the DMDC letter still holds.
- Whether clearance holders have any self-reporting obligation for being a breach victim. I did not verify that either way, so do not take silence as an answer; ask your security officer.
- The veteran and dependent share of the DMDC set.
I will update the status table as documents post. Each update will carry a date.
Frequently Asked Questions
Is the Pentagon breach and the FBI breach the same incident?
No. They are two separate events. According to Military Times' account of the DMDC notice letter, the Defense Manpower Data Center incident involved a file-sharing system where unauthorized users reached files with unencrypted personal information, and the notice letters are dated September 18, 2026. The FBI incident, as reported, involved the Oracle PeopleSoft database behind the FBIJobs.gov applicant portal and surfaced publicly on September 23. Nothing in the public record connects them. The only thing they share is the kind of data taken: Social Security numbers, dates of birth, and addresses.
How many people were affected by the DMDC breach?
A Pentagon official told TIME about 2.76 million living individuals and about 294,000 deceased individuals. An earlier press estimate said up to four million. Neither figure appears in a published Defense Department document, and DMDC's own public web portal carried no breach notice at all as of September 30, 2026. Use the roughly three million figure and call it reported, not confirmed.
What are DMDC breach victims being offered, and is there a deadline?
Twelve months of credit monitoring at no cost through IDX, the breach-response vendor named on the DMDC response page; enroll through that page. As of September 30, 2026 the IDX response page publishes no enrollment deadline, no identity-theft insurance amount, and no call-center hours. Enroll now rather than waiting for a deadline to be announced.
Is freezing my credit really free, and how fast can I unfreeze it?
Yes. Under 15 U.S.C. 1681c-1(i)(2)(A) a credit bureau must place a security freeze free of charge, within one business day of an electronic or telephone request. Removal is faster: the bureau has one hour to lift it when you ask by phone or through its secure site. You have to do it separately at Equifax, Experian, and TransUnion. A fraud alert is different: you contact one bureau and it must tell the other two, and an initial alert lasts at least one year.
Should I get an IRS Identity Protection PIN?
Yes, and you do not need to be a breach victim to qualify. The IP PIN is a six-digit number that stops someone else from filing a return with your Social Security number. Anyone with an SSN or ITIN who can verify their identity can opt in, the fastest route is your IRS online account, and the PIN is valid for one calendar year with a new one issued each year.
Can I sue the government over the breach?
The Privacy Act allows a suit, but the bar is high. Under 5 U.S.C. 552a(g)(4) you must show the agency acted intentionally or willfully, and recovery is actual damages with a $1,000 statutory floor, plus costs and fees. Claims generally carry a two-year limitations period under 552a(g)(5), with a discovery exception where the agency materially and willfully misrepresented information. The DMDC notice reportedly says there is no indication of misuse, which cuts against both damages and willfulness. Talk to a lawyer before assuming a per-person payout.
Related Resources
- OPM Breach Identity Protection Expires September 2026: What the 2015 victims are losing and when
- RECOVER PII Act: Lifetime Coverage for OPM Breach Victims?: The bill that would extend section 633
- Federal Employee NDA Rights: What you can and cannot be made to sign
Sources: 15 U.S.C. 1681c-1 (security freezes and fraud alerts) · IRS: Get an Identity Protection PIN · 5 U.S.C. 552a (Privacy Act civil remedies, subsection (g)) · Public Law 115-31, section 633 (2015 breach coverage mandate) · S. 5217, RECOVER PII Act, introduced text · OMB M-25-04, FY2025 FISMA guidance (major-incident definition) · the IDX DMDC response page, read September 30, 2026 · the DMDC public portal (dwp.dmdc.osd.mil), checked September 30, 2026 · reported details attributed in the text to Military Times (September 24), Federal News Network (September 28), and TIME (September 29).
