ADT Confirms Breach After ShinyHunters Claims 10 Million Records Stolen
A third breach in two years for the security company underscores how identity systems and SaaS environments remain prime targets for extortion groups.
Security Company Hit Again
On April 27, 2026, ADT confirmed a data breach after ShinyHunters claimed it stole 10 million records. ADT said payment information and customer security systems were not affected, though some records included dates of birth and partial Social Security or tax ID numbers. Have I Been Pwned later analyzed the leak and confirmed 5.5 million affected individuals, with data including names, phone numbers, addresses, and in some cases dates of birth and partial Social Security numbers.
This is ADT's third data breach in two years. Prior incidents occurred in August and October 2024. The incident highlights the growing risk of identity-focused attacks against companies that hold sensitive customer data, especially through cloud apps and employee access systems.
The ShinyHunters Pattern
ShinyHunters' 2026 campaign runs almost entirely on vishing attacks targeting Okta, Microsoft Entra, and Google SSO accounts to gain SaaS footholds across enterprises and business process outsourcing providers. A single SSO account without anomalous access detection opened an entire Salesforce environment in several documented cases.
In the ransomware attacks of April 2026, identity is consistently the entry point, not a vulnerability in the traditional sense. Security teams now face the reality that OAuth graphs and third-party app permissions have become the new perimeter, and most companies have no inventory of which apps their employees have authorized.
What the Data Shows
The gap between ADT's limited breach framing and the 5.5 million records confirmed in the wild is instructive. From a customer's standpoint, the question is not how limited the breach felt internally, but whether the exposed data fuels phishing and fraud. Encrypting and tokenizing sensitive fields inside CRM platforms, paired with monitoring for anomalous bulk export volumes, would have blunted both the theft and its aftermath.