By
Worldview Report, 06 October, 2026
Defense One reported this week that a Pentagon personnel breach and a separate FBI breach are raising the same old question: can the federal government even tell when it has been broken into?
The answer, on the evidence, is not for months.
Between October 2025 and July 16, 2026, unauthorized users reached a file-sharing system at the Defense Manpower Data Center. That office holds the personnel records the military and other agencies use. The files were not encrypted. They included Social Security numbers, and, depending on the person, names, dates of birth, contact information, and military job specialties. A defense official later put the exposure at about 2.76 million living people and another 294,000 who are deceased. Roughly three million records. Nine months of access. The flaw was patched after it was found. Affected people were offered a year of credit monitoring. That is the government’s idea of a response.
At the same time, the FBI is dealing with a separate intrusion claimed by the cybercrime group ShinyHunters. Reporting tied to that breach says sensitive records of personnel in intelligence and surveillance roles were exposed. No public evidence has linked the two intrusions. Both, though, hand an adversary a map of who works where, what they do, and how to impersonate them.
Nitay Milner of the data-security firm ORION put the real point in one sentence: three million people may be the headline, but months of unauthorized access to highly sensitive data going undetected is the warning. He is right. And he is describing the Pentagon and the FBI, not a county clerk’s office.
If the institutions charged with national defense cannot see a stranger in their own personnel files for the better part of a year, the country should stop pretending those same institutions are ready for a deliberate strike on the systems that keep daily life running.
Start with the banks. A payments system does not have to be destroyed to be crippled. It has to be distrusted. Freeze clearing. Corrupt account records. Knock out the networks that move payroll, card authorizations, and wire transfers. Households do not keep weeks of cash. Businesses do not keep weeks of operating money in a drawer. A serious disruption in the financial pipes is a disruption in food, fuel, and medicine within days, because those things are bought, not stockpiled, by most families.
Water treatment is worse, because it is quieter. In 2021 an intruder reached the controls of a plant in Oldsmar, Florida, and tried to raise the level of sodium hydroxide in the drinking water to a dangerous concentration. An operator noticed and reversed it. That was one plant, one attempt, caught by a person at a screen. There are thousands of water systems in this country. Many of them run on aging equipment, remote access, and a staff of a few people. A coordinated campaign does not need to poison a city. It needs to force plants offline, or force operators to stop trusting their own readings. Boil-water orders and tanker trucks are a local fix. They are not a national one.
The electric grid is the system everything else sits on. Pumps, card readers, traffic lights, cell towers, refineries, hospitals after the generators run down. Federal agencies have already warned that Chinese state-sponsored actors, tracked publicly as Volt Typhoon, have burrowed into American critical-infrastructure networks, not only to steal files but to be in position. Pre-positioned access is the point. The attacker does not have to win on the day of the strike. He has to be inside before the day arrives. Colonial Pipeline in 2021 showed what one ransomware hit on one fuel operator can do to the East Coast. That was crime. A state campaign against generation and transmission would not be solved by paying a bitcoin demand and restarting a billing server.
Then the FAA. In January 2023 the Notice to Air Missions system failed and flights across the country stopped. The government later blamed a damaged database file and a failure to follow procedure, not a hack. Remember that. The nation’s airspace was grounded by a file error and a bad process. If a clerical failure can halt departures, a deliberate attack on flight-data, radar-adjacent, or airline operational systems does not have to be exotic to produce the same picture: aircraft on the ground, crews out of position, cargo not moving. The FAA has spent years trying to modernize systems that still carry the habits of another era. Modernization is not the same thing as resilience under attack.
Here is the part official Washington will not say plainly. In a real strike on banks, water, power, and aviation at once, the federal government will not arrive with restoration crews in the first week. It will arrive with press conferences. The Pentagon could not see unauthorized users in a file share for nine months. The FBI is notifying its own people that criminal hackers reached personnel data tied to intelligence work. Treasury disclosed in 2024 that Chinese state-sponsored hackers had reached unclassified documents through a remote-support tool. The federal courts and the Congressional Budget Office have had their own intrusions. These are the scorecards of the institutions that would be asked to coordinate a national recovery.
Recovery from a grid event is measured in weeks for the hard-hit regions, and longer where large transformers or specialized control equipment are destroyed. Those are not items on a warehouse shelf. Water systems come back plant by plant. Banks come back when ledgers can be trusted again, which is a different problem from flipping a switch. Air travel comes back last, because it depends on power, communications, fuel, and confidence at the same time.
So the practical truth is this. If critical infrastructure is disrupted at scale, Americans will be on their own for weeks, and in the worst pockets for months. The household that has assumed the state will keep the lights on, the water safe, the card reader live, and the airport open is making a bet the recent record does not support. The government that cannot detect a nine-month breach of military personnel files is not a government prepared to win the first day of a real infrastructure war. It is a government that will learn it has been hit the same way it learned this time. Late.