
- The VA’s 2006 data breach exposed names, dates of birth, and Social Security numbers for 26.5 million veterans — one of the largest personal data breaches in U.S. history at that time.
- In 2024, the Change Healthcare cyberattack potentially exposed health data for at least 1.2 million veterans who used VA community care — the actual number may be higher.
- Veterans and active-duty military face statistically higher rates of identity theft than civilians, according to peer-reviewed research published in 2025.
- The VA offers free credit monitoring to veterans affected by specific breaches, but veterans must be notified by mail — checking proactively is not possible through the VA system.
- An active duty alert or credit freeze are the two most effective tools for veterans concerned about identity exposure from VA breaches.
Table of Contents
- The VA’s Breach History: What’s Happened to Your Data
- Why Veterans Are a Top Identity Theft Target
- What Information Was Exposed
- What the VA Does — and Doesn’t Do — After a Breach
- How to Protect Yourself Right Now
- If You’ve Already Been a Victim
- Identity Monitoring Options for Veterans
- Frequently Asked Questions
Veterans interact with the Department of Veterans Affairs repeatedly over years — disability claims, healthcare, education benefits, home loan certificates. Every interaction leaves a record. The VA holds more personal data on veterans than almost any other institution they deal with, and that data has been breached more than once.
Understanding what’s been exposed, what the VA does in response, and what you can do to protect yourself isn’t paranoia. It’s practical self-defense in a threat environment where veterans are documented targets.
Military.net is an independent educational resource not affiliated with the Department of Veterans Affairs or any government agency. For official breach notifications, visit VA.gov/privacy.
The VA’s Breach History: What’s Happened to Your Data
2006: The Laptop Breach — 26.5 Million Veterans
The largest breach in VA history occurred in May 2006 when a VA analyst took home a laptop and external hard drive containing personal data on 26.5 million veterans and active-duty service members. The devices — unencrypted — were stolen in a burglary. The hard drive contained names, dates of birth, and Social Security numbers for nearly all living veterans at the time.
The VA inspector general’s office found that cybersecurity officials had acted “with indifference and little sense of urgency” about the incident, and that the VA secretary was not informed about the breach for nearly two weeks after it occurred. Congress and affected veterans weren’t notified for nearly three weeks. The FBI eventually recovered the devices, and forensic analysis suggested the data was likely not accessed — but the breach permanently changed how the federal government handles data security.
2020: Financial Services Center Breach — 46,000 Veterans
The VA announced a breach in September 2020 involving the personal information of approximately 46,000 veterans. Unauthorized users accessed an online application at the VA’s Financial Services Center using social engineering techniques, gaining access to change financial information and divert payments from community health care providers. The VA took the application offline and offered free credit monitoring to affected veterans.
2024: Change Healthcare Cyberattack — At Least 1.2 Million Veterans
In February 2024, ransomware attackers hit Change Healthcare — the nation’s largest healthcare payment processor, which the VA uses to process payments for veterans receiving community care. The VA notified 15 million veterans that the breach might have exposed their private healthcare information, though the actual number of confirmed veteran victims was at least 1.2 million as of the most recent congressional update.
The House Committee on Veterans’ Affairs noted that despite the breach impacting the personal data of at least 1.2 million veterans, the committee had not received updated data about the number of affected veterans since August 2024 — and since UnitedHealth Group’s overall estimate of impacted individuals had nearly doubled from original estimates, the number of affected veterans could also be significantly higher.
The VA’s own systems were not breached — the vulnerability was in the private contractor’s network. But the result was the same for veterans: protected health information and personally identifiable information potentially in criminal hands.
Ongoing: Quarterly Congressional Reports
The VA is required by law to submit quarterly reports to Congress on data incidents. These reports are publicly available through the VA’s privacy office. Veterans who want to track VA data incidents can monitor these reports at VA.gov/privacy/privacy-reports.
Why Veterans Are a Top Identity Theft Target
Veterans’ elevated identity theft risk isn’t speculation. A 2025 peer-reviewed study using data from the National Crime Victimization Survey found that veterans and military service members face greater risk of both data breach victimization and identity theft than civilians, and that a positive association exists between data breach victimization and the odds of subsequent identity theft.
Several factors explain this elevated risk:
- High-value data concentration: Veterans’ files contain Social Security numbers, military service numbers, VA file numbers, medical records, financial information, and home addresses — all in one place. That combination is more valuable to identity thieves than any single data point.
- Government systems as targets: Federal agencies are disproportionately targeted by nation-state actors and sophisticated criminal organizations, not just opportunistic hackers.
- Third-party contractor exposure: The Change Healthcare breach illustrates how veterans’ data flows through private contractors who may have weaker security standards than the VA itself.
- Deployment-related vulnerability: Active-duty service members who are deployed may not monitor their credit or financial accounts for months, giving thieves a longer window to operate undetected.
- Stolen valor and benefits fraud: Some identity thieves specifically target veterans to fraudulently claim VA benefits using stolen identities — a crime that can take years to unravel.
What Information Was Exposed
Across the major VA breaches, the categories of information potentially exposed include:
| Breach | Information Type | Estimated Affected |
|---|---|---|
| 2006 Laptop | Name, date of birth, Social Security number, some disability ratings | 26.5 million |
| 2020 FSC Breach | Name, SSN, financial payment information | 46,000 |
| 2024 Change Healthcare | Protected health information, PII, treatment records | 1.2M+ confirmed |
Health information is particularly valuable to identity thieves because it can be used for medical identity theft — filing fraudulent insurance claims, obtaining prescriptions, or accessing medical care in a veteran’s name. Unlike financial fraud, medical identity theft can directly affect a veteran’s actual care if false information enters their medical record.
What the VA Does — and Doesn’t Do — After a Breach
When the VA confirms a breach affecting veterans’ personal information, its standard response includes:
- Mailing notifications to affected individuals
- Offering free credit monitoring services for a defined period (typically one year)
- Publishing information about the breach through official channels
- Reporting to Congress under its quarterly reporting requirement
What the VA does not do:
- Proactively alert veterans who weren’t directly affected but whose data may be at risk from third-party contractor breaches
- Provide permanent, ongoing credit monitoring regardless of breach status
- Allow veterans to proactively check whether their data was involved in a breach — you must receive a notification letter
If you received a VA notification letter about any breach, respond promptly. Enroll in the free credit monitoring offered — it’s typically provided through a major monitoring service and costs you nothing.
How to Protect Yourself Right Now
1. Place an Active Duty Alert (if currently serving)
Active-duty service members can place a free active duty alert with the three major credit bureaus — Equifax, Experian, and TransUnion. This requires creditors to verify identity before opening new accounts and restricts prescreened credit offers. Unlike a regular fraud alert, an active duty alert lasts 12 months and can be renewed.
2. Freeze Your Credit
A credit freeze is the most effective protection against new account fraud. It prevents anyone — including you — from opening new credit accounts until you temporarily lift the freeze. Freezes are free at all three bureaus under federal law and can be done online in minutes:
- Equifax: equifax.com
- Experian: experian.com
- TransUnion: transunion.com
You’ll need to freeze all three independently. When you need to apply for credit (VA loan, car loan, new credit card), you lift the freeze temporarily at the specific bureau the lender uses, then refreeze after.
3. Monitor Your Credit Reports
Every American is entitled to free weekly credit reports from all three bureaus at AnnualCreditReport.com. Review your reports for accounts you don’t recognize, addresses that aren’t yours, and inquiries from lenders you haven’t contacted.
4. Watch Your VA Account
Log in to VA.gov periodically and verify that your direct deposit information, mailing address, and contact details are correct. The 2020 FSC breach involved attackers changing payment information — monitoring your VA account for unauthorized changes is a direct defense against that attack vector.
5. Enable Two-Factor Authentication on VA.gov
Your VA.gov account contains your medical records, benefit history, payment information, and personal details. Enable two-factor authentication through the account settings. Use a strong, unique password not shared with any other account.
If You’ve Already Been a Victim
If you discover fraudulent accounts, unauthorized charges, or evidence of identity theft, take these steps:
- File an identity theft report at IdentityTheft.gov — the FTC’s official identity theft reporting and recovery portal. It generates a personalized recovery plan and creates an official report you can use with creditors and law enforcement.
- Place a fraud alert at all three credit bureaus — this is separate from a freeze and puts creditors on notice that your identity may have been compromised.
- Report to the VA’s Privacy Service if you believe the fraud is connected to a VA breach — call 202-273-5070 or contact VA.gov/privacy.
- File a police report — some creditors require it to dispute fraudulent accounts.
- Contact the CFPB at consumerfinance.gov/complaint if a financial institution isn’t cooperating with fraud disputes.
Identity Monitoring Options for Veterans
Beyond free credit freezes and annual credit reports, several paid identity monitoring services are worth considering for veterans with elevated risk. When evaluating services, look for:
- All three credit bureau monitoring (not just one)
- Dark web scanning for your SSN, email, and financial account numbers
- Social Security number monitoring
- Identity theft insurance ($1 million+ coverage is standard in quality services)
- U.S.-based restoration assistance — a human specialist who helps resolve identity theft, not just alerts
Frequently Asked Questions
How do I know if my data was in the 2006 VA breach?
The VA sent notification letters at the time to affected veterans. If you were on active duty or were a veteran in 2006 and did not receive a letter, the VA’s position is that your data was not involved — but given that 26.5 million records were affected, veterans from that era should assume their basic identifying information (name, DOB, SSN) may have been exposed and take protective measures accordingly.
Does the VA provide ongoing free identity monitoring?
No. The VA offers free credit monitoring for a defined period (typically one to two years) following specific breaches to affected veterans. There is no permanent, ongoing monitoring program for all veterans. Veterans must arrange their own monitoring beyond the breach-specific offering.
Can I find out if my VA account has been accessed without my knowledge?
Log in to VA.gov and review your account activity, contact information, and payment details for anything you don’t recognize. The VA does not provide a full access log to users, but unauthorized changes to payment information or addresses are often the first sign of VA account compromise.
Is medical identity theft from the Change Healthcare breach covered by insurance?
Standard identity theft protection services typically cover financial identity theft — fraudulent credit accounts, loans, and similar. Medical identity theft coverage varies by service and policy. Review your specific plan’s terms, and if medical identity theft is a concern, look for a service that explicitly covers medical record fraud and restoration.
Are veterans protected by HIPAA if their VA medical data is breached?
The VA is subject to privacy laws governing federal agencies, including the Privacy Act of 1974, which is separate from HIPAA. Private contractors like Change Healthcare that handle VA patient data are subject to HIPAA. Veterans whose protected health information was exposed in the Change Healthcare breach have rights under HIPAA’s breach notification requirements, which require notification and an explanation of what was compromised.
This article is provided by Military.net, an independent educational resource not affiliated with the Department of Veterans Affairs or any government agency. For official VA privacy information, visit department.va.gov/privacy.


