2026年9月25日 美国东部时间下午4:18 / 美国有线电视新闻网(CNN)
作者:肖恩·林加斯、戴维斯·温基
凯文·拉马克/路透社
五角大楼庞大的人事系统发生数据泄露事件,导致现役及退伍军人的社会保险号码等个人信息被泄露,引发了国家安全专家的反情报担忧。
据美国国防人力数据中心(DMDC)致受害者的一封信件(由CNN审阅)显示,“未经授权的用户”自去年10月起侵入该中心一台存在安全漏洞的计算机服务器,但直到9个月后的今年7月,五角大楼才发现并修复了这一问题。
根据该中心官网信息,截至2024财年,国防人力数据中心至少保管着6000万条记录。目前尚不清楚受影响人数,但《军事时报》报道称,多达400万名国防部人员可能受到此次泄露事件的影响。
根据这封信件,五角大楼目前“没有任何迹象表明泄露的数据被滥用”。但专家表示,对于试图追踪美国军人的外国情报机构,或是企图勒索军人的网络犯罪分子而言,这些泄露的数据无异于一座潜在的“金矿”。
这封落款为本月的信件显示,入侵者在部分案例中还获取了军人的“职业专长”信息。若将这类信息与社会保险号码等标识符的其他数据集结合,外国对手就能更清楚地了解全球各地美军人员的具体岗位。
目前尚不清楚此次攻击的幕后黑手。五角大楼发言人未立即回应CNN的置评请求,包括嫌疑人身份在内的多个问题均未得到回复。
美国军方领导人曾多次警告部队,在与伊朗的冲突期间,军人的手机和在线账户可能成为攻击目标。负责中东及周边地区事务的美国中央司令部今年春季曾向议员表示,该机构“收到多份威胁报告,称对手利用商业位置数据瞄准或监视战区内的美军人员”。
咨询公司Global Cyber Strategies首席执行官贾斯汀·谢尔曼(同时也是一本即将出版的关于数据经纪行业书籍的作者)表示,恶意行为者可将从国防人力数据中心窃取的信息与其他商业数据集结合,“根据国防人员的收入、债务、婚姻状况、消费习惯、浏览活动等信息,了解甚至瞄准他们”。
根据该中心官网介绍,国防人力数据中心是国防部关于军人、退伍军人及其家属福利、津贴和“医疗战备情况”信息的“单一核心访问点”。
“我们提供的服务和数据访问支持了众多关键政府机构,”国防人力数据中心官网写道,“包括立法部门、公共服务、国防、劳工、医疗、金融、退伍军人事务、科研等众多领域。”
根据信件内容,被盗数据未进行加密处理,而加密敏感数据是一项标准的安全操作规范。
“我们正在采取适当措施,评估并加强国防人力数据中心系统的网络安全态势,”信件在为受害者提供一年期信用监控服务的同时写道。
“在美国与伊朗开战、并与多个其他大国处于竞争关系的当下,仅就有多达数百万军人的个人信息遭到泄露这一点而言,就已十分危险,”谢尔曼告诉CNN,“如果外国对手获取这类数据宝库,将可能催生网络钓鱼、身份画像、外国情报策反等诸多风险。”
Pentagon data breach of military personnel raises national security concerns
2026-09-25 4:18 PM ET / CNN
By Sean Lyngaas, Davis Winkie
Members of the military attend a meeting convened by US Defense Secretary Pete Hegseth, at Marine Corps Base Quantico, in Virginia, September 30, 2025.
Kevin Lamarque/Reuters
A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national security experts.
“Unauthorized users” gained access to a vulnerable computer server belonging to the Defense Manpower Data Center (DMDC) beginning last October, but it wasn’t until nine months later, in July, that the Pentagon discovered and remediated the issue, according to a letter the center sent to victims of the breach reviewed by CNN.
The DMDC maintained at least 60 million records as of fiscal 2024, according to its website. It’s unclear how many have been impacted, but Military Times reported that four million Department of Defense personnel could be affected by the breach.
The Pentagon currently “does not have any indications of misuse” of the breached data, according to the letter. But the breached data is a potential goldmine for foreign intelligence services looking to track US military personnel, or cybercriminals looking to extort them (were they to acquire the data), according to experts.
One piece of data accessed by the intruders in some cases was the “occupational specialty” of military service members, according to the letter, which is dated this month. That, when combined with other datasets using identifiers like Social Security numbers, could give foreign adversaries a clearer read on who does what for the US military in various parts of the world.
It’s unclear who was behind the breach. A Pentagon spokesperson did not immediately respond to CNN’s questions, including who the culprit was.
US military leaders have repeatedly warned their troops that their phones and online accounts could be targets during the war with Iran. US Central Command, which spans the Middle East and beyond, told lawmakers in the spring that it had “received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil US personnel in theater.”
A bad actor could pair the information taken from DMDC with other commercial datasets to “learn about or even target [defense personnel] based on their earnings, debts, marriages, spending habits, browsing activities, and worse,” said Justin Sherman, CEO of advisory firm Global Cyber Strategies and the author of an upcoming book on the data broker industry.
The DMDC is “the one, central access point” for information on Department of Defense entitlements, benefits and “medical readiness” for military personnel, veterans and their families, according to the center’s website.
“The services and access to data we provide support so many vital government entities,” the DMDC website says, “including the legislative branch, human services, national defense, labor, healthcare, finance, veterans affairs, research, and more.”
The stolen data wasn’t encrypted, according to the letter. Encrypting sensitive data is a standard security practice.
“We are taking appropriate actions to assess and enhance the cybersecurity posture of the DMDC system,” the letter says while offering victims a year of credit monitoring services.
“On its own, having personal data on potentially millions of service members exposed is dangerous as the US wages war on Iran and is in competition with multiple other governments,” Sherman told CNN. “If a foreign adversary was to get this kind of data trove, it could enable phishing, profiling, foreign intel approaches, and much more.”
发表回复