US Army Contractor Exposed Sensitive Military Base Data in Major Security Lapse

A US government contractor responsible for providing facility management services to the American military has reportedly exposed tens of thousands of sensitive files linked to military installations, raising serious concerns over cybersecurity and national security risks.

According to a new investigation by Cybernews, an unsecured online directory belonging to CMI Management Inc. left at least 70,000 files openly accessible for months, despite warnings reportedly being sent to authorities.

The issue first came to light after security researcher Arkadeep Roy alerted the Cybernews research team on March 16. Roy claimed he had already notified the US Computer Emergency Readiness Team (US-CERT), but the exposed data remained accessible during the subsequent investigation.

Researchers said the leak stemmed from an “Open Directory Listing Vulnerability”, which allowed unrestricted public access to files stored within the directory due to a lack of proper security controls.

The exposed information reportedly included photographs taken inside military bases, building schematics, maintenance work orders and personally identifiable information relating to both military personnel and contractors.

Cybersecurity analysts warn that the data could present a significant intelligence opportunity for hostile actors. Detailed schematics and infrastructure documentation could potentially help build a clearer picture of military base layouts and operational structures beyond what is visible through satellite or aerial imagery alone.

Security experts also warned that sensitive personal information contained within the files could expose military staff and contractors to phishing attacks, identity theft and social engineering campaigns designed to gain further access to secure systems or facilities.

The report suggests nation-state actors and cybercriminal groups could potentially exploit the leaked information to identify weaknesses in infrastructure, operational procedures or contractor relationships linked to US military operations.

The incident once again highlights growing concerns surrounding third-party cybersecurity risks within government supply chains. Contractors handling sensitive public sector and defence information are increasingly becoming targets for cyberattacks and scrutiny as agencies rely more heavily on external service providers and digital infrastructure.

The exposure also raises broader questions about vulnerability disclosure processes and response times. Despite the alleged notification to US-CERT, the files reportedly remained accessible while the investigation was ongoing.

Neither CMI Management nor US authorities had publicly commented on the findings at the time of reporting.

The full investigation, including technical details surrounding the exposure, has been published by Cybernews Research.