ADT Confirms Breach After ShinyHunters Claims 10 Million Records Stolen

A third breach in two years for the security company underscores how identity systems and SaaS environments remain prime targets for extortion groups.

Illustration: ADT Confirms Breach After ShinyHunters Claims 10 Million Records Stolen
AI-generated illustration · Sylvaris

Security Company Hit Again

On April 27, 2026, ADT confirmed a data breach after ShinyHunters claimed it stole 10 million records. ADT said payment information and customer security systems were not affected, though some records included dates of birth and partial Social Security or tax ID numbers. Have I Been Pwned later analyzed the leak and confirmed 5.5 million affected individuals, with data including names, phone numbers, addresses, and in some cases dates of birth and partial Social Security numbers.

This is ADT's third data breach in two years. Prior incidents occurred in August and October 2024. The incident highlights the growing risk of identity-focused attacks against companies that hold sensitive customer data, especially through cloud apps and employee access systems.

The ShinyHunters Pattern

ShinyHunters' 2026 campaign runs almost entirely on vishing attacks targeting Okta, Microsoft Entra, and Google SSO accounts to gain SaaS footholds across enterprises and business process outsourcing providers. A single SSO account without anomalous access detection opened an entire Salesforce environment in several documented cases.

In the ransomware attacks of April 2026, identity is consistently the entry point, not a vulnerability in the traditional sense. Security teams now face the reality that OAuth graphs and third-party app permissions have become the new perimeter, and most companies have no inventory of which apps their employees have authorized.

What the Data Shows

The gap between ADT's limited breach framing and the 5.5 million records confirmed in the wild is instructive. From a customer's standpoint, the question is not how limited the breach felt internally, but whether the exposed data fuels phishing and fraud. Encrypting and tokenizing sensitive fields inside CRM platforms, paired with monitoring for anomalous bulk export volumes, would have blunted both the theft and its aftermath.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.