Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationvoice-social-engineeringmass-credential-exposureunderground-data-leak

ADT Confirms Customer Data Breach After ShinyHunters Extortion Claim

Updated 2mo agoFirst seen Apr 24, 202615 sources

ADT disclosed that attackers gained unauthorized access to certain cloud-based environments and stole customer and prospective customer data, prompting the company to activate incident response measures, engage forensic specialists, notify law enforcement, and contact affected individuals. The exposed information included names, phone numbers, and home addresses, with dates of birth and the last four digits of Social Security numbers or Tax IDs affected in a smaller number of cases; ADT said payment information was not accessed and customer home security systems were not impacted.

The disclosure followed claims by the ShinyHunters extortion group that it had stolen more than 10 million records and internal corporate data and would leak the information if its demands were not met. Reporting tied the intrusion to a suspected vishing attack that allegedly compromised an employee's Okta single sign-on account and enabled access to ADT's Salesforce environment, matching a broader pattern in which the group targets enterprise SSO accounts and connected SaaS platforms to steal data for extortion.

Share:
ADT Confirms Customer Data Breach After ShinyHunters Extortion Claim
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Apr 27, 20262mo ago

ShinyHunters leaks 11GB of ADT data after failed extortion

After ADT reportedly refused the extortion demand, ShinyHunters published an 11GB archive of allegedly stolen ADT data on its dark web leak site. The leak marked an escalation from the group's earlier threat to release the data unless ADT made contact.

Home security giant ADT data breach affects 5.5 million people

Reporting links ADT breach to Okta social engineering and Salesforce access

Independent reporting indicated the attackers may have socially engineered an ADT employee to gain access to the company’s Okta environment and then exfiltrated data from Salesforce. The reported intrusion path aligned with a broader ShinyHunters pattern of targeting single sign-on platforms and Salesforce-related data stores.

Home Security Firm ADT Breach: 5.5M Customers' Data Exposed

Have I Been Pwned lists 5.5 million emails from ADT breach

Independent reporting said Have I Been Pwned added 5.5 million unique email addresses linked to the ADT incident. The listing suggested the breach may be significantly larger than ADT's public description of the stolen data.

Burglar alarm biz gets burgled, ShinyHunters pursues ransom • The Register
Apr 24, 20262mo ago

ADT offers identity protection to affected individuals

As part of its response, ADT directly notified impacted people and offered complimentary identity protection services where appropriate. The company said its investigation was ongoing and it did not believe the incident would materially affect business operations.

ADT files SEC disclosure confirming the breach

ADT disclosed the incident in an SEC Form 8-K filed on 2026-04-24, confirming unauthorized access and theft of limited customer and prospective customer data. The company said it had engaged third-party forensic experts, notified law enforcement, and begun notifying affected individuals.

Apr 23, 20262mo ago

ShinyHunters claims ADT breach and threatens data leak

On 2026-04-23, the ShinyHunters extortion group claimed on its leak site that it had stolen more than 10 million ADT records and internal corporate data. The group threatened to leak the data unless ADT made contact by 2026-04-27.

Apr 20, 20262mo ago

ADT investigates theft of customer and prospect data

Following the intrusion, ADT determined that customer and prospective customer personal information was stolen, primarily names, phone numbers, and addresses, with dates of birth and last four digits of Social Security numbers or Tax IDs exposed in a smaller number of cases. ADT said payment information was not accessed and customer security systems were not affected.

ADT detects and contains unauthorized access to cloud environments

ADT detected unauthorized access to certain cloud-based environments on 2026-04-20 and terminated the intrusion. The company activated its incident response plan and began investigating the breach.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

34 LINKEDOpen in app
Threat actors
1 linked
Affected products
2 linked
ZendeskDropbox
Organizations
31 linked
AdtSalesforceOktaHave I Been PwnedMicrosoft CorporationGoogleMedtronicAmtrakBleepingComputerCarnival CorporationRockstar GamesZendeskAtlassianSAPDropboxAdobeSlack TechnologiesMcGraw-HillMatch GroupThe Register7-ElevenUnit 221BBumbleUdemyPCMagCanada GooseMercer AdvisorsBeacon Pointe AdvisorsZaraCarnival Corporation & plcADT Inc.
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

ADT Confirms Customer Data Breach After ShinyHunters Extortion Claim | Mallory