{"id":12393,"date":"2026-04-25T10:05:03","date_gmt":"2026-04-25T10:05:03","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/25\/adt-confirms-data-breach-following-shinyhunters-data-leak-claim\/"},"modified":"2026-04-25T10:05:03","modified_gmt":"2026-04-25T10:05:03","slug":"adt-confirms-data-breach-following-shinyhunters-data-leak-claim","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/25\/adt-confirms-data-breach-following-shinyhunters-data-leak-claim\/","title":{"rendered":"ADT Confirms Data Breach Following ShinyHunters Data Leak Claim"},"content":{"rendered":"<p>    ADT Confirms Data Breach Following ShinyHunters Data Leak Claim<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Home security giant ADT Inc. has confirmed a data breach after the notorious threat group ShinyHunters claimed to have stolen over 10 million records and issued a ransom ultimatum \u2014 \u201cPay or Leak.\u201d<\/p>\n<p>ADT, headquartered in Boca Raton, Florida, disclosed the incident via a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC) on April 24, 2026, stating that it became aware of unauthorized access to certain cloud-based environments on April 20, 2026.<\/p>\n<p>The incident came to light after ShinyHunters posted a listing on their dark web data leak site, claiming to have compromised \u201cover 10 million records containing PII and other internal corporate data.\u201d The group issued a chilling final warning: <em>\u201cReach out by 27 Apr 2026 before we leak, along with several annoying (digital) problems that\u2019ll come your way.\u201d<\/em><\/p>\n<p>ShinyHunters claimed the breach was carried out through a <a href=\"https:\/\/cybersecuritynews.com\/arsen-launches-ai-powered-vishing-simulation-to-help-organizations-combat-voice-phishing-at-scale\/\" target=\"_blank\" rel=\"noreferrer noopener\">voice phishing (vishing) attack<\/a> that successfully compromised an employee\u2019s Okta single sign-on (SSO) account.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiE2Tqpl_zsMeWHcgdC2GWGFghLqbrDRj2QMSM61MBcPorIxiRMd8S8d9EUnKKDyqrn_FloDS0iXy-H3Nm3mFNSQ-aIGqLLykUl9-b5-mvlE7s5rO2UdnY49_hwueQEgKd_u61jM4FBS-Bd6AuaDWR91jVffSJfvuVNFQqWSErzKPzioVECCr9lYy6Trrf2\/s16000\/ADT%2520Confirms%2520Data%2520Breach.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>Using this foothold, the threat actors allegedly accessed and exfiltrated data from ADT\u2019s Salesforce instance. This tactic, impersonating IT support to manipulate employees into granting internal system access, is a hallmark method associated with ShinyHunters\u2019 operations.<\/p>\n<p>ADT\u2019s investigation determined that the exposed data was limited to a set of customer and prospective customer records. According to PCMag, the compromised information primarily included names, phone numbers, and home addresses.<\/p>\n<p>In some cases, dates of birth and the last four digits of Social Security numbers or Tax IDs were also included. ADT confirmed that no financial information, such as bank account or credit card data, was accessed, and that customer home security systems remained secure and fully operational.<\/p>\n<p>Upon detecting the intrusion, ADT promptly terminated the unauthorized access, activated its Incident Response Plan (IRP), engaged third-party cybersecurity experts for a forensic investigation, and notified law enforcement.<\/p>\n<p>The company stated it has \u201cdirectly notified all impacted individuals\u201d and will provide complimentary identity protection services where necessary.<\/p>\n<p><a href=\"https:\/\/d18rn0p25nwr6d.cloudfront.net\/CIK-0001703056\/eb8645ea-ddea-4d52-8ebb-2d72eed935da.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ADT\u2019s 8-K filing stressed that the company<\/a> does not believe the incident is \u201creasonably likely to have a material impact\u201d on its financial condition or ongoing business operations, though the full scope of the breach remains under assessment.<\/p>\n<p>This is not ADT\u2019s first rodeo with data breaches. The company previously disclosed two separate security incidents in August and October 2024, both of which exposed customer and employee information.<\/p>\n<p>The latest ShinyHunters extortion campaign raises serious questions about ADT\u2019s cloud security posture and access control hygiene, particularly around employee authentication mechanisms like SSO platforms. With the threat actor\u2019s April 27 deadline looming, the security community is closely watching whether ADT will comply, negotiate, or call the bluff.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/adt-confirms-data-breach\/\">ADT Confirms Data Breach Following ShinyHunters Data Leak Claim<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/adt-confirms-data-breach\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>ADT Confirms Data Breach Following ShinyHunters Data Leak Claim Home security giant ADT Inc. has confirmed a data breach after the notorious threat group ShinyHunters claimed to have stolen over 10 million records and issued a ransom ultimatum \u2014 \u201cPay or Leak.\u201d ADT, headquartered in Boca Raton, Florida, disclosed the incident via a Form 8-K [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-12393","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12393"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12393"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12393\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12393"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12393"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}