Bonfy Blog

What Nine Months of Undetected Exposure Teaches Us About File-Sharing Governance

Written by Gidi Cohen | 10/6/26, 7:49 PM

When the Defense Manpower Data Center discovered unauthorized access on July 16, 2026, the attackers had already spent nine months inside their file-sharing server. Those nine months span 274 days during which 2.76 million living individuals and 294,000 deceased people—military personnel, civilian employees, contractors, family members, retirees, and veterans—had their Social Security numbers, names, dates of birth, contact information, and military occupational specialties sitting in plain view. No one on the DMDC team noticed. The notification letter went out in September, more than a month after the discovery. This is not a story about a determined attacker who broke through a fortress. It is a story about an absence of visibility into what was actually happening on a system the Pentagon trusted to house its most sensitive personnel data.

Key Takeaways

  • 2.76 million people exposed because one file-sharing server lacked monitoring and encryption—a visibility, not access, problem
  • A nine-month exposure window before detection signals a governance failure in how data flow is observed, not just controlled
  • File-sharing systems without real-time audit logging and per-file access controls create compliance blind spots for regulated industries
  • Enterprise file-sharing solutions must answer the question: Do you know what data is on the system, who accessed it, and when?

The Anatomy of a Preventable Exposure

The DMDC operates the military's single source of truth for personnel records—60 million of them. On the surface, this looks like a breach story: attackers found a way in, stole data, and left no traces until someone spotted them months later. The real story is simpler and more damning. The Pentagon did not notice because they were not looking. A file-sharing server holding unencrypted PII for 274 days without detection is not a failure of perimeter defense. It is a failure of internal visibility. No unusual access patterns triggered an alert. No baseline of normal access was established. No log retention existed that could have closed that nine-month window to nine days, or nine hours. The DMDC notification letter describes the exposed system as 'a file sharing system' and 'a server'—a specific content channel, not a vague 'IT system.' When you operate a file-sharing system, you must answer: Who can access which files, at what time, and why? If you cannot answer that question in real time, you have visibility blindness.

Learn more about Kiteworks Control Plane data governance and secure file sharing architecture.

Unencrypted Data and the Compliance Reckoning

The exposed data sat unencrypted. That is a detail worth pausing on. In 2026, unencrypted PII on a server holding military personnel records is not a technical oversight—it is a compliance posture. The DMDC operates under federal recordkeeping and security standards. Each of those 2.76 million people exposed has a claim on the Pentagon's duty to safeguard their data. When data is encrypted at rest and in transit, and access is logged, a nine-month exposure window becomes impossible. An attacker who steals encrypted files gets gibberish. An attacker who accesses a server logs an access event that shows up in an audit trail. The Pentagon's file-sharing server had neither safeguard firing on all cylinders. Why? Because visibility and encryption cost money, and file-sharing systems optimized for ease of use often ship with both turned down. Bonfy and Kiteworks solve this problem by sitting between the data and whoever is trying to reach it—observing, classifying, and enforcing—so that compliance teams know what data is flowing and to whom.

Explore Bonfy's approach to Shadow AI governance and Kiteworks' audit logging and encryption features.

 

The Shadow File-Sharing Problem

The DMDC incident is not unique because the DMDC is uniquely important. It is unique because someone actually noticed and disclosed it. Across enterprises today, unmonitored file-sharing systems are the norm. A developer shares a folder with a contractor who leaves the company but keeps access. A manager keeps an open shared drive with customer PII because it is easier than managing individual access. An AI agent configured to reach a SharePoint or Google Drive instance downloads files that should have required approval. None of these scenarios trigger alerts because the file-sharing system has no visibility into intent or risk. Bonfy's role is to answer the question: What data is actually flowing through these systems, and does it belong there? When you lose control of the answer, you lose the ability to detect the DMDC's nine-month exposure window in weeks instead of months.

See how Bonfy enables compliance monitoring in real time.

From Detection to Prevention

The Pentagon eventually caught the breach because someone ran a scan or noticed anomalies after discovery (the exact detection method is not disclosed in public notices). But a nine-month detection window is the real scandal. In a system built with Bonfy and Kiteworks' architecture, that window shrinks. Real-time logging shows who accessed what, encryption means stolen data is worthless, and per-file access controls mean a file-sharing server can distinguish between a legitimate administrator and an intruder. These are not theoretical advantages. They are the difference between a discovery nine months after breach and a response three hours after the first unusual access pattern fires. The DMDC's response will now include notification, credit monitoring, and reputation damage. Had the exposure been caught in the first week, those costs vanish.

Discover real-time access controls that prevent prolonged exposure.

FAQs

1. Why didn't the Pentagon encrypt the data at rest if it was so critical?

The DMDC notification letter does not explain the design choice. In practice, file-sharing systems often ship without-at-rest encryption enabled by default because encryption adds latency and complexity. Compliance teams and security architects must choose encryption explicitly. The DMDC apparently did not, or the system did not support it. A governance failure, not a technical limitation.

2. Could Bonfy and Kiteworks have stopped this breach before it happened?

Bonfy works by sitting between an AI application and the data it tries to access, enforcing policies in real time. Kiteworks operates as a control plane for secure file exchange. Neither would have prevented the initial unauthorized access to the Pentagon's file-sharing server unless the server itself was running Kiteworks' secure file sharing architecture or Bonfy's classification layer was observing access. However, once the attacker had access, Kiteworks' per-file access controls and Bonfy's real-time audit logging would have reduced the nine-month exposure window to hours or days. This is the difference between reactive breach response and proactive compliance visibility.

3. Is the Pentagon unique, or are other government agencies at similar risk?

Government agencies and large enterprises rely heavily on legacy file-sharing systems because they were the standard before cloud-native secure exchange became available. Many operate with similar visibility blind spots. The DMDC incident is notable because it was disclosed; many similar breaches never reach public notice because the victim organization delays notification or keeps breaches quiet. If you cannot answer the question 'Who accessed which files, and when?' in real time, you are operating a DMDC-like system.

4. How should an organization prevent this from happening internally?

Three answers: (1) Encrypt data at rest and in transit. (2) Log all access and review logs regularly. (3) Implement per-file access controls so not everyone with server access can read everything. If your file-sharing system cannot do all three, you have a governance gap.

5. Why is this a Bonfy issue as well as a Kiteworks issue?

Bonfy classifies what is happening at the data layer—what files are being accessed, whether they contain PII, whether the access is anomalous. Kiteworks governs the secure exchange of those files and provides the infrastructure to enforce policies. Together, they solve the DMDC problem: Bonfy tells you what is flowing, Kiteworks makes sure only the right people and systems can access it. If you have file-sharing governance in place but lack real-time classification, you have half the solution.

Next Steps

The Pentagon's nine-month exposure is a reminder that visibility and encryption are not nice-to-have features; they are compliance requirements. Download our Data Visibility Checklist to audit your current visibility posture and identify governance gaps in your file-sharing systems.

Gidi Cohen, VP Product, Kiteworks

Gidi leads product strategy for Kiteworks and Bonfy.AI. He has spent his career solving the problem of how organizations govern sensitive data in motion, at rest, and in use—for humans and AI agents alike.