US government cybersecurity

Two Federal Breaches in One Week Show That Government Cyber Mandates Are Failing at Enforcement, Not Rule-Writing

A Pentagon file-server leak and an FBI PeopleSoft intrusion expose a gap between directives on paper and patching in practice.

Federal Breaches and Compliance Gaps People of Internet Research · US 3M+ People in DMDC breach About 2.8M living and 294,000 dece… 86% Agencies missing cloud deadline 88 of 102 agencies, per DHS inspec… 3 days Fastest BOD 26-04 deadline For exposed, automatable, known-ex… peopleofinternet.com
Federal Breaches and Compliance Gaps People of Internet Research · US 3M+ People in DMDC breach 86% Agencies missing cloud deadline 3 days Fastest BOD 26-04 deadline peopleofinternet.com

Key Takeaways

In the same week, two of the federal government's most security-conscious institutions told people their Social Security numbers had been taken. The Defense Manpower Data Center (DMDC) disclosed that a flaw in a file-sharing system exposed records on more than 3 million people. Separately, the FBI told staff to assume hackers had stolen personal data tied to its jobs portal. Neither incident involved a novel technique. Both involved ordinary, well-understood failures: unencrypted data and an unpatched enterprise application.

What the public record shows

According to Federal News Network, the DMDC breach affected about 2.8 million living people and roughly 294,000 deceased individuals with military ties. Unauthorized access ran from October 2025 through July 2026. The vulnerability was identified and patched on July 16, 2026. The exposed information was unencrypted and included names, dates of birth, Social Security numbers and military job specialties. The Pentagon says it has no evidence of misuse. Affected people are being offered 12 months of credit monitoring through IDX. Military Times reported that notification letters went out on September 18. Its sources put the possible total nearer 4 million, so the final count may move.

The FBI case is less settled. TechCrunch reported on September 28 that the bureau had told staff to assume their names, addresses, job titles and Social Security numbers had been stolen. The attackers reportedly exploited a vulnerability in an Oracle PeopleSoft server holding human-resources data for applicants to its job portal. The group ShinyHunters claimed responsibility. Publicly, the FBI had said only that the theft of data was "still undetermined." Much of the detail comes from internal notices and press reports, not an official public statement. Treat the specifics accordingly.

The strongest case for tougher mandates

The case for harsher rules is serious. The government holds data that adversaries value. Service records and agent identities are useful to foreign intelligence services and extortionists alike. Voluntary good practice has demonstrably not been enough. The Federal Information Security Modernization Act of 2014 (Public Law 113-283) has required agency security programs for over a decade, and breaches keep recurring. Advocates of stricter liability, mandatory encryption at rest and personal accountability for agency heads argue that only consequences change behavior.

Why the problem looks like enforcement, not missing rules

The rulebook is already thick. In June 2026, CISA issued Binding Operational Directive 26-04. It sets risk-based remediation clocks as short as three days for publicly exposed, automatically exploitable, known-exploited flaws that give an attacker full control of a system. A file-sharing server or an internet-facing HR portal is exactly the asset class those timelines target. The directive's flaw is not its content. It is whether anyone can make agencies comply.

The evidence says they cannot. CyberScoop reported on September 23 on a DHS inspector general report. It found that 88 of 102 agencies, or 86%, had not implemented all mandatory cloud-security policies by the June 2025 deadline. The IG concluded that "CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives." A rule that carries a deadline but no consequence functions as a suggestion.

That matters for how Congress should respond. The reflexive answer to a breach is new mandates, new reporting layers and new compliance checklists. More paperwork, though, tends to reward agencies that document well, not agencies that defend well. A proportionate response would be narrower and easier to measure.

What proportionate reform looks like

A pro-innovation stance does not mean tolerance for lax defense. Public trust in government digital services, and in the private firms that supply them, depends on the state meeting at least the standard it expects of industry. Contractors and vendors such as PeopleSoft's maintainers should face clear, predictable patch-disclosure expectations. Broad liability regimes that chill software development would not help.

What to watch

Two questions will determine whether these incidents change anything. First, will the FBI and the Pentagon publish post-incident findings, including how long the DMDC flaw was exploitable and why detection took until July 2026? Second, will Congress act on the inspector general's finding about CISA's authority? If the answer to both is no, expect another disclosure of the same kind within months. The tools exist. The missing piece is accountability for using them.

Sources & Citations

  1. Federal News Network: DMDC breach
  2. TechCrunch: FBI cyber security incident
  3. Military Times: breach notification
  4. CyberScoop: DHS IG on CISA directives
  5. BleepingComputer: CISA BOD 26-04
  6. FISMA 2014 (Public Law 113-283)