字号 ·· | 护眼
techcrunch

黑客在长达数月的数据泄露事件中窃取了数百万份美军人员记录Hackers stole millions of US military personnel records during months-long data breach

点「原文对照」整页切到原文,或双击某段只看那段的原文。

据报道,美国政府正在通知数百万现役和前美国军事服务人员及工作人员,他们的个人信息在持续数月的五角大楼人事记录泄露事件中被盗,这是近几个月来涉及联邦工作人员数据被盗的一系列事件中的最新一起。

The U.S. government is reportedly alerting millions of current and former U.S. military service members and staff that their personal information was stolen during a months-long breach of the Pentagon’s personnel records, the latest in a spate of thefts involving federal workers’ data in recent months.

一份在Reddit上分享的国防人力数据中心(DMDC)数据泄露通知称,几名未经授权的用户在2025年10月至2026年7月中旬的几个月里,利用一个未指明的文件共享系统中的安全漏洞。

A data breach notification from the Defense Manpower Data Center (DMDC) shared on Reddit says that several unauthorized users exploited a security vulnerability in an unspecified file-sharing system over several months between October 2025 and mid-July 2026.

此次泄露暴露了个人身份信息,包括社会安全号码,以及姓名、出生日期、性别、种族和其他军事服务信息。通知称,人事记录未加密。

The breach exposed personally identifiable information, including Social Security numbers, alongside a person’s name, date of birth, sex, race, and other information about their military service. The notice says that the personnel records were unencrypted.

据CNN和联邦新闻网报道,一名五角大楼官员表示,此次泄露影响约280万在世人员,以及近30万已故人员。截至3月,美军有130万现役服役人员。

According to CNN and Federal News Network, a Pentagon official said the breach affects about 2.8 million living people, and close to 300,000 people who are deceased. The U.S. military has 1.3 million active service members as of March.

DMDC可能不为大众广泛所知,但它是国防部的档案保管单位之一。DMDC为美国军事和文职人员及其家属维护超过6000万条记录,以帮助确定福利和权利,如医疗保健和退休金。该单位还作为军队的“领先身份管理提供商”提供关键服务,将现役服役人员、雇员和承包商与凭证(如智能卡和密码)关联起来。这些凭证用于访问五角大楼的计算机系统、建筑物和基地。

The DMDC may not be widely known to the general public, but serves as one of the Department of Defense’s records-keeping units. The DMDC maintains over 60 million records for U.S. military and civilian staff and their family members to help determine benefits and entitlements, such as healthcare and retirement. The unit also provides a critical service as the military’s “leading identity management provider,” which links active service members, employees, and contractors to credentials, such as smart cards and passwords. These are used to access Pentagon computer systems, buildings, and bases.

DMDC网站上写道:“我们确保正确的人获得访问权限,而错误的人无法访问:身份信息的安全至关重要。”

“We make sure that the right people get access and the wrong people don’t: security of identity information is paramount,” the DMDC’s website reads.

国防部负责监管DMDC,表示没有迹象表明该信息被滥用,但未说明得出该结论的依据。TechCrunch联系了五角大楼发言人,询问官方是否收到过黑客的通讯(黑客身份不明),但未收到回复。

The Department of Defense, which oversees the DMDC, said it does not have any indication that the information was misused, but did not say how it reached that conclusion. TechCrunch contacted a Pentagon spokesperson to ask if officials had any communications from the hackers, whose identities are not known, but we did not hear back.

这是近几个月来联邦工作人员个人信息发生的最新重大泄露事件,此前9月初FBI刚遭遇归因于ShinyHunters黑客组织的泄露事件。黑客告诉TechCrunch,他们窃取了大多数FBI特工和员工(包括申请人)的个人信息。鉴于外国政府可能获取并利用这些信息对联邦工作人员进行画像、锁定目标或胁迫其交出敏感信息的风险,此次泄露被称为“反情报灾难”。

This is the latest major breach of federal workers’ personal information in recent months, following a recent breach at the FBI earlier in September attributed to the ShinyHunters hacking group. The hackers told TechCrunch that they had taken the personal information of most of the FBI’s agents and staffers, including applicants. The breach has been billed as a “counterintelligence disaster” amid the risks that a foreign government could obtain and use the information to profile, target, or coerce federal workers into handing over sensitive information.

ShinyHunters黑客表示,他们不会公开发布窃取的FBI数据。

The ShinyHunters hackers have said that they will not publicly release the stolen FBI data.

涉及FBI和DMDC的这两起泄露事件,与过去发生的政府人员档案被盗案件如出一辙。2015年,美国政府人力资源部门——人事管理办公室遭遇泄露,普遍被归因于中国。那次窃取事件导致黑客窃取了2200多万名美国政府雇员的私人档案,其中许多人持有安全许可。

Both breaches involving the FBI and the DMDC mirror similar thefts of government personnel records in the past. In 2015, a breach of the U.S. government’s human resources department, known as the Office of Personnel Management, was broadly attributed to China. The theft allowed the hackers to steal the private records of more than 22 million U.S. government employees, many of whom had security clearances.