In the same week, two of the federal government's most security-conscious institutions told people their Social Security numbers had been taken. The Defense Manpower Data Center (DMDC) disclosed that a flaw in a file-sharing system exposed records on more than 3 million people. Separately, the FBI told staff to assume hackers had stolen personal data tied to its jobs portal. Neither incident involved a novel technique. Both involved ordinary, well-understood failures: unencrypted data and an unpatched enterprise application.
What the public record shows
According to Federal News Network, the DMDC breach affected about 2.8 million living people and roughly 294,000 deceased individuals with military ties. Unauthorized access ran from October 2025 through July 2026. The vulnerability was identified and patched on July 16, 2026. The exposed information was unencrypted and included names, dates of birth, Social Security numbers and military job specialties. The Pentagon says it has no evidence of misuse. Affected people are being offered 12 months of credit monitoring through IDX. Military Times reported that notification letters went out on September 18. Its sources put the possible total nearer 4 million, so the final count may move.
The FBI case is less settled. TechCrunch reported on September 28 that the bureau had told staff to assume their names, addresses, job titles and Social Security numbers had been stolen. The attackers reportedly exploited a vulnerability in an Oracle PeopleSoft server holding human-resources data for applicants to its job portal. The group ShinyHunters claimed responsibility. Publicly, the FBI had said only that the theft of data was "still undetermined." Much of the detail comes from internal notices and press reports, not an official public statement. Treat the specifics accordingly.
The strongest case for tougher mandates
The case for harsher rules is serious. The government holds data that adversaries value. Service records and agent identities are useful to foreign intelligence services and extortionists alike. Voluntary good practice has demonstrably not been enough. The Federal Information Security Modernization Act of 2014 (Public Law 113-283) has required agency security programs for over a decade, and breaches keep recurring. Advocates of stricter liability, mandatory encryption at rest and personal accountability for agency heads argue that only consequences change behavior.
Why the problem looks like enforcement, not missing rules
The rulebook is already thick. In June 2026, CISA issued Binding Operational Directive 26-04. It sets risk-based remediation clocks as short as three days for publicly exposed, automatically exploitable, known-exploited flaws that give an attacker full control of a system. A file-sharing server or an internet-facing HR portal is exactly the asset class those timelines target. The directive's flaw is not its content. It is whether anyone can make agencies comply.
The evidence says they cannot. CyberScoop reported on September 23 on a DHS inspector general report. It found that 88 of 102 agencies, or 86%, had not implemented all mandatory cloud-security policies by the June 2025 deadline. The IG concluded that "CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives." A rule that carries a deadline but no consequence functions as a suggestion.
That matters for how Congress should respond. The reflexive answer to a breach is new mandates, new reporting layers and new compliance checklists. More paperwork, though, tends to reward agencies that document well, not agencies that defend well. A proportionate response would be narrower and easier to measure.
What proportionate reform looks like
- Give CISA verification authority. Let it test whether directive deadlines were met on internet-facing systems, using external scanning, and report agency-level results publicly. Transparency is cheaper and less distorting than punitive regimes.
- Make data minimization the default. The DMDC exposure involved Social Security numbers sitting unencrypted on a file server across roughly nine months. Agencies should not hold sensitive identifiers they do not need, and should encrypt the ones they must keep.
- Fund the boring work. Patching, asset inventory and legacy-application retirement rarely win appropriations, yet they close the doors attackers actually use.
- Avoid expanding surveillance or access mandates as a remedy. Breaches of government-held data are an argument for holding less of it, not for building larger centralized stores.
A pro-innovation stance does not mean tolerance for lax defense. Public trust in government digital services, and in the private firms that supply them, depends on the state meeting at least the standard it expects of industry. Contractors and vendors such as PeopleSoft's maintainers should face clear, predictable patch-disclosure expectations. Broad liability regimes that chill software development would not help.
What to watch
Two questions will determine whether these incidents change anything. First, will the FBI and the Pentagon publish post-incident findings, including how long the DMDC flaw was exploitable and why detection took until July 2026? Second, will Congress act on the inspector general's finding about CISA's authority? If the answer to both is no, expect another disclosure of the same kind within months. The tools exist. The missing piece is accountability for using them.