Breach Watch, September 29, 2026: Pentagon Personnel Agency Breach Exposes 3 Million People
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · September 29, 2026

TL;DR for CISOs: A Pentagon personnel data center disclosed that a file-sharing flaw exposed Social Security numbers and other records of about 3 million people over roughly nine months. France's tax authority lost data on more than 600,000 people to stolen staff passwords on portals with no second factor, and the theft went unnoticed for seven weeks. Apple patched a CoreGraphics zero-day used in a targeted attack.

BOTTOM LINE FOR CISOS
  1. Long dwell time is the real cost. Both government incidents ran for weeks to months because a system was outside patch scope or outside monitoring. Coverage gaps, not clever techniques, set the breach window.
  2. A password alone is still enough to reach sensitive data in places you may not have looked. Check MFA enforcement and session revocation on internal portals, not only on your main SSO.
  3. Sensitive identity data belongs behind encryption and access logging wherever it lives. If SSNs sit unencrypted in a shared system, the next file-sharing flaw becomes a mass exposure.

Lead story: A Pentagon personnel data center exposed Social Security numbers of about 3 million people for roughly nine months

CRITICAL · GOVERNMENT PERSONNEL DATA
Key facts
Organization: Defense Manpower Data Center (DMDC), the Department of Defense agency that maintains personnel records
Exposed data: Names, Social Security numbers, dates of birth, contact details, demographic information and military occupational specialties; SecurityWeek reports the records were unencrypted
Scale: About 2.76 million living individuals and 294,000 deceased individuals, per the notification as reported by SecurityWeek; Federal News Network rounds this to about 2.8 million living and 294,000 deceased
Cause: A vulnerability in a DMDC file-sharing system that allowed unauthorized users to access files; the product is not named in the notification
Exposure window: Roughly October 2025 through mid-July 2026; the flaw was found and fixed in July 2026 (SecurityWeek gives July 16 as the discovery date)
Notification: Letters dated September 18, 2026; 12 months of credit monitoring through IDX, per Federal News Network
Attribution and misuse: No group has claimed the incident, and DMDC says it has no indication the information has been misused

What happened

Letters from the Defense Manpower Data Center began reaching affected people this month, and coverage broadened on September 29. According to SecurityWeek, the agency found a security flaw in one of its file-sharing systems on July 16, 2026. The flaw let unauthorized users open files they should not have been able to reach, and access appears to have gone back to October 2025.

The files held core identity data on service members and others in DoD personnel systems: Social Security numbers, dates of birth, contact details and job specialties. Roughly 294,000 of those affected are deceased. DMDC says it patched the vulnerability, restored the system and started incident response, and that it has no indication of misuse so far.

Several questions remain open. Federal News Network reports that officials did not say who gained access or why the data was stored without encryption, and the file-sharing product has not been named. Treat any claim about who was behind it, or how much was copied, as unconfirmed.

Evidence

Verified against independently fetched sources:
1. SecurityWeek, Pentagon personnel agency data breach impacts 3 million people, September 29, 2026
2. Federal News Network, More than 3 million people affected by military data breach, September 2026

What this means for your team

The point for a CISO is the duration, not the headline count. A file-sharing system was reachable by people who should not have had access for about nine months, and nothing surfaced until July. That is a detection and inventory problem as much as a patching one: many organizations run internal file-transfer and sharing tools that sit outside the vulnerability program because the business owns them.

The second lesson is data minimization. Records that include Social Security numbers were reportedly stored unencrypted on a system reachable through a file-sharing flaw. If your teams keep identity documents or SSNs in shared drives, transfer tools or exports, assume those are the first files an intruder opens.

If you support federal contractors or hire from the veteran and service-member population, expect this data to fuel targeted phishing and identity fraud against your staff and customers for years. Plan awareness messaging and fraud monitoring accordingly.

Action checklist
  1. Inventory every internet-reachable or partner-reachable file-sharing and managed file-transfer system, including ones owned by business units, and confirm each has a named owner and is in patch scope.
  2. Scan shared repositories and transfer directories for files containing SSNs and other identity data, then encrypt, tokenize or delete what has no business need to sit there.
  3. Turn on access logging for file-sharing platforms and alert on bulk downloads or access from accounts that do not normally use them; test whether you could reconstruct nine months of access if asked.
  4. Check whether your workforce or customer base includes affected populations, and brief your fraud and help-desk teams on identity-verification abuse using SSNs and dates of birth.

France's tax authority breach: stolen staff passwords, no second factor, and seven weeks before anyone noticed

HIGH · CREDENTIAL THEFT
Key facts
Organization: DGFiP, France's public finance directorate (tax administration)
Scale: Reports vary by outlet: The Hacker News cites more than 350,000 individuals and more than 250,000 businesses, and Bitdefender reports about 678,000 people and professionals
Exposed data: Tax identifiers, contact details, family situation, reference income and withholding rates, property addresses and business SIREN numbers; message content was also taken for fewer than 250 individuals and 2,076 businesses, per The Hacker News
Method: Passwords stolen from staff personal devices, likely by infostealers, used on two portals that required only a password, per The Hacker News citing the national cybersecurity agency ANSSI's report
Detection gap: Data theft began in June; the incident surfaced August 12 when the attacker claimed it publicly, about seven weeks after first extraction
What was not stolen: Bitdefender reports that taxpayers' own online account usernames and passwords were not taken

What happened

The Hacker News reports that ANSSI's post-incident findings show a plain attack path. Attackers logged in with valid staff passwords that had been stolen from personal devices. Two portals accepted a password alone, so no second factor stood in the way, and separation between networks was weak.

Monitoring caught part of it. According to The Hacker News, the security operations team flagged a suspicious login on June 23 and reset the password the next morning, but the attacker's already-open session on a second portal stayed alive for another 16 hours and about 11 GB of data left that system. That portal was not monitored at all.

Totals differ between outlets, so treat any single figure with care until the agency publishes its own count.

Evidence

Verified against independently fetched sources:
1. The Hacker News, French tax data theft using stolen staff passwords went undetected for seven weeks, September 29, 2026
2. Bitdefender, French tax authority data breach affects 678,000

What this means for your team

Three ordinary control gaps combined here: password-only access to sensitive portals, incomplete log coverage, and a password reset that did not end an active session. None is exotic, and each is likely present somewhere in your estate.

The infostealer detail matters most for scoping. Credentials taken from personal devices never touch your endpoint tooling, so device controls will not see the loss. Only identity-layer signals, such as new locations, unusual data volumes and session anomalies, will.

A useful test for your own program: pick your five most sensitive internal portals and ask whether each enforces MFA, feeds your SIEM, and revokes sessions when a password is reset. Any no is a finding.

Action checklist
  1. List every application holding regulated or sensitive data and confirm MFA is enforced for all users, including staff and administrators, with phishing-resistant methods where available.
  2. Confirm each of those applications sends authentication and data-export logs to your SIEM, and add alerts for large downloads by a single account.
  3. Update the account-compromise runbook so a password reset also revokes active sessions and tokens across every connected application.
  4. Subscribe to infostealer credential-exposure monitoring for your domains and staff, and treat a hit as an incident that requires a reset and session revocation.

Apple patches CoreGraphics zero-day used in an 'extremely sophisticated' targeted attack

HIGH · ACTIVELY EXPLOITED
Key facts
Vulnerability: CVE-2026-86950, an out-of-bounds write in CoreGraphics
Exploitation: Apple says it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27
Reporter: Meta's product security team
Fixed in: iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1
Affected devices: iPhone 11 and later, supported iPad models, and Macs running the affected macOS versions
Impact: Processing a maliciously crafted file can lead to arbitrary code execution

What happened

Apple released security updates on September 29, 2026 for a CoreGraphics flaw that it says may have been used against specific targeted people. The company credits Meta's product security team with the report. Apple did not name the victims or the attacker.

The fix is a bounds-check change in the rendering framework. Exploitation appears to have been limited to iOS versions before iOS 27, according to Apple's statement as reported by SecurityWeek, and Apple has not said how the malicious files reached targets.

Attacks of this kind are typically aimed at a small number of high-value individuals, such as executives, journalists, and government and security staff.

Evidence

Verified against independently fetched sources:
1. BleepingComputer, Apple patches CoreGraphics zero-day flaw exploited in attacks, September 29, 2026
2. SecurityWeek, Apple patches Meta-reported zero-day linked to extremely sophisticated attack, September 29, 2026

What this means for your team

Most of your fleet is not the target of a mercenary-grade exploit, but your executives, board members and public-facing staff might be. The practical question is how quickly the most exposed people get patched, not how quickly the average device does.

Mobile is also where many organizations have the weakest visibility. If you cannot report which OS version your leadership team's phones run today, this is the week to find out.

For people who believe they may be targeted, Apple's Lockdown Mode is an available option, and it is worth offering to that group.

Action checklist
  1. Push the September 29 updates to managed iPhones, iPads and Macs, and prioritize executives, the board and staff in sensitive roles.
  2. Pull an OS-version report for all managed and BYOD Apple devices and follow up on anything still running below 26.7.1 or 15.8.1.
  3. Check that your mobile device management policy can enforce a minimum OS version and block non-compliant devices from corporate email and SSO.
  4. Offer Lockdown Mode and a direct reporting channel to high-risk individuals who see unexpected crashes or unusual behavior.

Also notable

  • Star Blizzard phishing campaign reaches 100+ organizations. Microsoft reports the Russia-linked group has used fake event invitations, including ones impersonating well-known policy institutions, against organizations mainly in the US and UK since January, delivering a Python backdoor called CosmicPulse. Source: The Hacker News
  • 101 malicious npm packages abuse a WhatsApp library. OX Security identified 101 packages, downloaded about 490,000 times, that silently add developers' WhatsApp accounts to attacker-controlled channels. The stated purpose is spam promotion rather than data theft. Source: The Hacker News
  • New Spectre v2 variant affects Intel, AMD and Arm CPUs. SecurityWeek reports the branch-target attack variant can leak data through JIT compilers, language runtimes and the OS kernel; BleepingComputer reports it can recover Linux root password hashes in minutes. Source: SecurityWeek
  • OpenSSL and wolfSSL ship patches for roughly a dozen vulnerabilities each. SecurityWeek reports the fixes were released September 30, so check your dependency inventory for both libraries. Source: SecurityWeek
  • Dutch police arrest a 24-year-old in Amsterdam in a ShinyHunters investigation. The Hacker News reports the arrest is tied to the group's data theft and extortion activity; details on the suspect's role were limited at the time of reporting. Source: The Hacker News

Frequently asked questions

What data did the Defense Manpower Data Center breach expose?

DMDC reported that names, Social Security numbers, dates of birth, contact details, demographic information and military occupational specialties were accessible to unauthorized users through a vulnerable file-sharing system. About 2.76 million living and 294,000 deceased individuals were affected, and DMDC says it has no indication of misuse.

How long were the Pentagon records exposed?

According to SecurityWeek, unauthorized access was possible from about October 2025 until the flaw was found and fixed in July 2026, roughly nine months. Notification letters are dated September 18, 2026.

How did attackers get into the French tax authority's systems?

The Hacker News, citing the ANSSI report, says attackers used staff passwords stolen from personal devices, likely through infostealers, on two portals that did not require a second factor. Monitoring gaps let the theft continue for about seven weeks.

Which Apple devices need the CoreGraphics update?

Apple fixed CVE-2026-86950 in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Affected hardware includes iPhone 11 and later and supported iPad and Mac models. Apple says the flaw may have been used in an extremely sophisticated attack on specific targeted individuals.

What should a CISO do first this week?

Confirm MFA and logging on every application that holds sensitive data, inventory file-sharing and file-transfer systems, and push the Apple updates to executives and other high-risk users. Those three steps address the gaps seen in today's incidents.

CISO Platform Breach Intelligence Team
Curated by Pritha Aash, Community Head, CISO Platform. Breach Watch is a daily briefing for senior security leaders, built from verified reporting and written for the person who has to decide what the team does about it before lunch.
NETWORK · SHARE · LEARN
Security leaders compare notes on incidents like these every day inside the CISO Platform community. Joining is free.

Related reading from the community: past editions in the Breach Intelligence briefing archive, practitioner material on identity security for security leaders, guidance on third-party and vendor-risk frameworks, and the wider library of frameworks and checklists on CISO Platform.

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.
★
★
★
★
★
Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion