Skip to content
HackInvasionCybersecurity Knowledge Hub

Daily Cyber Threat Brief — October 1, 2026: Pentagon DMDC breach exposes personnel data of 3M+


 

🗂️ CASE FILE — October 1, 2026

Lead story: The Pentagon's Defense Manpower Data Center (DMDC) is notifying more than 3 million people — nearly 2.8 million living individuals plus 294,000 deceased — that hackers stole their personal data after breaching the Pentagon's human-resources management system. A "small number of unauthorized users" had access to Social Security numbers, names, dates of birth, contact information, sex, race, and military personnel data between October 2025 and July 2026 by exploiting a vulnerability in DMDC's file-sharing systems. The Pentagon is offering 12 months of IDX credit monitoring; a spokesperson was not available for comment.

Also covered: ShinyHunters' website went offline Wednesday, a day after its FBI deadline expired — as the FBI's Cyber Division chief publicly urges remaining members to turn themselves in, Reuters confirms medical and psychiatric records in the stolen sample, and the group insists it never planned to leak the data · MetaMask discloses an ongoing infrastructure security incident, says there's no immediate threat to wallets, and is proactively exiting affected Ethereum validators · DIVD attributes its own network breach to two Zammad zero-days (CVE-2026-102489, CVE-2026-102490) chained by an autonomous AI agent that escalated to root in seconds · McMinnville, Oregon breach notice fallout: a local researcher found police, medical, and HR files on RansomHouse's leak site in three clicks, with 53,000 visits logged · Ransomware claims: Laboratorios Roemmers (aurora, Argentina pharma), Houston Thyroid & Endocrine Specialists (N0n, 14,441 patient scans, Oct 4 deadline), Dynamic Office Solutions (Qilin), The Japan Times (Eclipse).

Sources: 6 linked at the end of this brief.

Today's top stories

The federal-government breach beat dominates today: the Pentagon is notifying more than 3 million military personnel, family-adjacent individuals, and others that their records were taken from the Defense Manpower Data Center — a file-sharing vulnerability exploited for nine months — while the ShinyHunters–FBI saga enters its post-deadline phase with the group's site dark, the FBI publicly calling for surrenders, and Reuters confirming the stolen sample includes psychiatric records. Meanwhile, MetaMask's infrastructure incident and DIVD's AI-driven zero-day breach are both reminders that the trust layer — wallet infrastructure, vuln-disclosure nonprofits — is now the target, and McMinnville's slow municipal breach notice turned into a live dark-web case study. All of that, plus today's ransomware claims, below.

Pentagon DMDC breach: personnel records of more than 3 million stolen via file-sharing vulnerability

The Pentagon's Defense Manpower Data Center is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system. In breach-notification letters shared online by affected individuals, the DMDC said a "small number of unauthorized users" had access to sensitive data, including personally identifiable information, between October 2025 and July 2026 after exploiting a vulnerability in its file-sharing systems. The stolen data varies by person and includes Social Security numbers, names, dates of birth, contact information, sex, race, and military personnel information.

Pentagon officials told Federal News Network the breach affects more than 3 million people, including nearly 2.8 million living individuals and 294,000 "deceased individuals." "Upon discovery of the security vulnerability, DMDC immediately initiated privacy and cybersecurity incident response actions in accordance with Office of Management and Budget and Department guidelines and policies," the DMDC told affected individuals. The Pentagon is offering 12 months of free credit monitoring through IDX, with enrollment required by August 19, 2027. A Pentagon spokesperson was not immediately available for comment when BleepingComputer reached out.

Founded in 1974, the DMDC is an operational support center storing more than 60 million military, civilian, contractor, family member, retiree, and veteran records used to authorize benefits and entitlements. This is the second federal personnel-data mega-breach in the headlines in two weeks — following the ShinyHunters FBIJobs.gov incident — and raises the same counterintelligence exposure questions: SSNs, duty assignments, and identity data at this scale are a targeting gold mine for foreign actors.

🔍 Investigation notes — defender takeaway (click to expand)

Nine months of unauthorized access through a file-sharing vulnerability is the detail that matters most: the initial vector wasn't a sophisticated APT chain, it was a file-sharing system — the same class of perimeter-adjacent application (NetScaler, PeopleSoft, now DMDC file-sharing) that keeps producing mega-breaches. Defenders should note: (1) file-sharing appliances and transfer services need the same hardening regime as edge VPN/gateway gear — internet-facing inventory hygiene applies; (2) with 3M+ records mixing living and deceased individuals, expect the data to surface in fraud and synthetic-identity schemes for years — the 294,000 deceased individuals are prime synthetic-identity feedstock; (3) the bureaucratic response lag (breach window closed July 2026, letters surfacing October 1) means defenders relying on government-adjacent notification feeds should expect long disclosure tails.

ShinyHunters site goes offline after FBI deadline; bureau urges members to surrender; Reuters confirms psychiatric records

The ShinyHunters website went offline Wednesday, a day after the group's deadline for the FBI to retract or modify its May 2026 advisory expired — the reasons for the outage have not been reported, per TechNadu/Reuters. The blackout caps a week of escalating moves around the FBIJobs.gov breach: on Tuesday, FBI Cyber Division assistant director Brett Leatherman released a video thanking Dutch police for arresting a 24-year-old man believed to be a member of the group — described by the FBI as one of the alleged leaders — and warning remaining members that the arrest changes the calculus and they should contact the agency "while the choice is still yours."

The arrested man, detained in Amsterdam on September 15, was identified by KrebsOnSecurity as Pepijn van der Stap, offensive security lead at Dutch company Neo Security, previously known under the alias Umbreon — separately suspected of attempting to arrange two murders. ShinyHunters denies any association with him. Meanwhile, Reuters analysis of the stolen sample confirmed it includes medical and psychiatric information alongside extensive PII and job-role data, and the group told Cybernews it never planned to publish the data or demand a ransom, calling the one-week ultimatum a "marketing campaign" and insisting "nothing will happen" — a statement that, as Undercode News noted, reduces fears of an immediate mass dump without resolving whether the alleged 2–3 TB dataset exists or remains in unauthorized hands.

🔍 Investigation notes — defender takeaway (click to expand)

Treat the post-deadline posture as theater, not resolution: a group's website going dark after its deadline says nothing about where the data went or who holds copies — samples were already shared with multiple media outlets. Three defender-relevant threads: (1) PeopleSoft remains the urgent remediation target — Google GTIG detailed ShinyHunters dropping web shells on unpatched instances via CVE-2026-35273; any PeopleSoft estate still unpatched is an active intrusion risk; (2) the medical/psychiatric data confirmation escalates the incident from a contact-list leak to a deeply sensitive exposure — family-member and health details multiply both the physical-safety and counterintelligence risk for affected personnel; (3) the public "turn yourselves in" posture signals the FBI is pursuing attribution in the open — expect follow-on arrests or indictments, each likely to trigger retaliation-adjacent activity from the group's remaining operators.

MetaMask discloses ongoing infrastructure security incident; exits affected validators as precaution

Cryptocurrency wallet provider MetaMask disclosed Thursday an ongoing infrastructure security incident affecting some of its infrastructure. The company says it is working to address the issue internally with external partners and security advisors, and that there is "no immediate threat to MetaMask wallets." "As a precautionary measure, we are proactively exiting affected validators within our non-custodial staking operations, in coordination with clients and partners," MetaMask noted, adding that its staking operations are non-custodial and it does not manage withdrawal keys on behalf of clients.

MetaMask declined to say which part of its infrastructure was affected or whether any systems or data were accessed or compromised. Separately, Lido Finance said MetaMask Staking (formerly Consensys Staking) has begun exiting its Ethereum validators in the Lido protocol, with the final validators expected to be exited by the end of October 7, 2026 — incurring foregone rewards and possible downtime penalties. The non-custodial wallet, developed by Consensys, is one of the most widely used Ethereum wallet providers, and the disclosure lands one week after Bitget detailed its own $387.5M wallet-infrastructure compromise.

🔍 Investigation notes — defender takeaway (click to expand)

An infrastructure incident at the wallet layer deserves attention even with "no immediate threat" language: MetaMask declining to name the affected infrastructure or confirm whether data was accessed is standard early-stage opacity, but the validator-exit move is a costly precaution (foregone rewards + penalties) that suggests the company is treating this as serious internally. For defenders: (1) watch for phishing and social-engineering waves piggybacking on this disclosure — breach-adjacent scams spike after wallet-provider incidents; (2) the Bitget parallel from last week (zero-day in third-party security products, $387.5M) means crypto infrastructure is firmly in the adversary spotlight — if your org touches custody or staking operations, re-baseline vendor trust assumptions; (3) the October 7 validator-exit deadline is the next milestone to watch for the incident's real blast radius.

DIVD: AI agent chained two Zammad zero-days to breach security nonprofit's network in seconds

The Dutch Institute for Vulnerability Disclosure (DIVD) says its network breach was made possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system, now identified as CVE-2026-102489 and CVE-2026-102490. The nonprofit — which coordinates vulnerability disclosure and internet scanning — previously described the attack as "loud and very, very messy," driven by an AI agent that moved autonomously and decided its next steps without external intervention. Because the agent left behind clear explanations of its decisions, DIVD could reconstruct the incident in detail.

"Used together, they allowed the attackers to hijack sessions, run code remotely, and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack," DIVD says. The attacker accessed other services and exfiltrated data before network segmentation and incident-response actions stopped deeper lateral movement; the investigation is ongoing. Zammad — an open-source helpdesk platform with over 2,000 customers and 55,000 users, including De'Longhi, Amnesty International, and NextCloud — was notified; DIVD discovered the flaws with Merlon Security and recommends users upgrade to version 7 (considered safe) or take instances offline immediately.

🔍 Investigation notes — defender takeaway (click to expand)

This is the first high-profile confirmed case of an autonomous AI agent executing a full kill chain — session hijack to RCE to root to exfiltration in seconds — against a security organization, and it's a milestone worth sitting with. The operational lesson cuts both ways: (1) patching windows for internet-facing helpdesk/ticketing platforms must be measured in days, not cycles — agentic attackers compress exploitation from hours to seconds, and Zammad's 2,000+ customers are now racing the same disclosure; (2) segmentation is what saved DIVD — the agent was contained by network architecture, not by detecting the agent itself, which is the control that scales against machine-speed attacks; (3) the agent's self-documenting decision trail was a forensic gift this time — assume the next generation won't leave notes, and baseline "loud, messy, machine-speed" behavior as its own detection category.

McMinnville, Oregon: leaked city files — police, medical, HR — took three clicks to find on RansomHouse leak site

Detailed reporting published October 1 by KOIN 6 News and local Fox affiliate KPTV has turned the City of McMinnville, Oregon breach into a live case study in slow municipal disclosure. The city of roughly 34,300 people confirmed unauthorized access to its systems between June 1 and July 18, 2026, but did not issue its formal breach notice until September 29 — more than ten weeks after it first spotted the intrusion on July 15. In between, ransomware group RansomHouse posted what it described as proof of stolen files on its leak site on August 6.

The discovery driving the story: Chuck Dornon, CEO of McMinnville-based security firm Alexonet and a city resident himself, has been monitoring dark-web leak sites since learning of the breach August 6. "Three clicks. That's all it took to reach private McMinnville records that should never have been public," he told KOIN — and by his count the leak site had logged 53,000 visits as of late September. The city's notice lists names, driver's license numbers, and Social Security numbers; Dornon's review of the leaked files went further — tax returns, stored passwords, bank records, HR files, confidential police records including what appeared to be witness interview material, medical information, and municipal court records. The city has set up an assistance line (1-833-544-7562, weekdays 5 a.m.–5 p.m. PT). Dornon has publicly argued the 76-day notice timeline exceeds what Oregon law allows; the city says its investigation was only "in-part complete" by September 22.

🔍 Investigation notes — defender takeaway (click to expand)

The gap between the legal-baseline notice (SSNs, driver's licenses) and what was actually sitting on the leak site (police witness interviews, HR files, tax returns) is the consequential detail — leaked police investigative material carries safety implications beyond identity theft, and the notice arguably under-described the exposure. For defenders and municipalities: (1) dark-web monitoring is a baseline control, not an add-on — an independent researcher found the leak two months before the city's own public notice; (2) the "notify fast vs. notify accurately" tension is real, but a 76-day gap with files publicly downloadable will be the exhibit in every future state-AG enforcement action; (3) small-city network architecture concentrates risk — police, courts, HR, and finance sharing infrastructure means one compromise is a whole-government exposure.

Ransomware leak-site claims roundup

Fresh claims from the last 24 hours. None are independently confirmed; treat each as a threat-actor claim, not a confirmed breach:

  • aurora hits Laboratorios Roemmers SAICF (discovered October 1). Argentina's largest pharmaceutical company by revenue is listed with claimed exfiltration of 4,207 employee national identity numbers (CUIL) tied to dates of birth and health-insurance affiliations, plus psychotropic drug dispensing records, COVID-19 health logs, doctor's notes, and pre-employment medical exams — and 82 GB of pharmaceutical IP including drug formulations and API synthesis methods, 193 MB of supplier qualification dossiers, and 14 GB of pricing strategy. Infostealer activity (Cavalier stealer) is linked to the incident; Hudson Rock reported 53 compromised users and 1,395 passwords. The IP angle makes this the highest-value claim of the day.
  • N0n targets Houston Thyroid & Endocrine Specialists (Oct 1). The Houston endocrinology practice is listed with 14,441 patient document scans — lab results, medical summaries, diagnoses, insurance records, and day sheets — including SSNs, dates of birth, clinical data, and billing records. The group set a data-publication deadline of October 4, 2026 at 12:00 UTC. If confirmed, a significant PHI exposure.
  • Qilin claims Dynamic Office Solutions (Oct 1). Sparse details so far — one compromised user account and three exposed passwords linked to infostealer activity. Watch for escalation or a data volume update.
  • Eclipse targets The Japan Times (Sept 30). Listed with claimed infostealer infection (Cavalier stealer): 5 employee credentials, 621 user accounts, 2,672 passwords (9 critical), and 10,609 cookies exposed.
🔍 Investigation notes — defender takeaway (click to expand)

Today's claims are heavy on health-sector and infostealer-linked entries — consistent with 2026's pattern of stealer-first initial access feeding ransomware operations. The Roemmers claim stands out: pharmaceutical IP theft at 82 GB plus psychotropic dispensing records is a double regulatory-and-competitive nightmare for Argentina's largest drugmaker. The Houston Thyroid deadline (Oct 4) is the near-term clock to watch. As always: claims precede confirmation, some listings are bluffs, and none of these are verdicts.

Incident timeline

DateEventStatus
Oct 2025 – Jul 2026Unauthorized access to DMDC file-sharing systems; personnel data of 3M+ exfiltratedConfirmed via Pentagon breach letters
Jun 1 – Jul 18, 2026McMinnville, OR: unauthorized access window per city investigationConfirmed by city
Jul 15McMinnville detects "unusual activity"; investigation beginsConfirmed by city
Aug 6RansomHouse lists City of McMinnville on its leak siteThreat-actor claim
Sep 24DIVD discloses network breach; attack path via Zammad zero-days identified Sep 30Confirmed by DIVD
Sep 29FBI Cyber Division video urges ShinyHunters members to turn themselves in; McMinnville issues formal breach noticeConfirmed
Sep 30ShinyHunters website goes offline (per TechNadu/Reuters); MetaMask discloses infrastructure incidentConfirmed reporting
Oct 1Pentagon DMDC breach notification letters surface (BleepingComputer); KOIN/KPTV publish McMinnville leak details; aurora/Roemmers, N0n/Houston Thyroid, Qilin/Dynamic Office, Eclipse/Japan Times claimsConfirmed / claims
Oct 4N0n data-release deadline for Houston Thyroid & Endocrine Specialists claimUpcoming
Oct 7MetaMask expects final affected validators exited (not fully withdrawn)Upcoming

Sources

  1. Hackers stole Pentagon personnel records of over 3 million people — BleepingComputer
  2. MetaMask discloses security incident affecting its infrastructure — BleepingComputer
  3. DIVD says Zammad zero-days enabled AI-driven network breach — BleepingComputer
  4. ShinyHunters Website Goes Offline After FBI Deadline Passes — TechNadu
  5. McMinnville Data Breach: 53K Visits to Leaked Records — Tech-Insider
  6. FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader — Bitdefender
Latest


EmoticonEmoticon