ADT disclosed that attackers gained unauthorized access to certain cloud-based environments and stole customer and prospective customer data, prompting the company to activate incident response measures, engage forensic specialists, notify law enforcement, and contact affected individuals. The exposed information included names, phone numbers, and home addresses, with dates of birth and the last four digits of Social Security numbers or Tax IDs affected in a smaller number of cases; ADT said payment information was not accessed and customer home security systems were not impacted.
The disclosure followed claims by the ShinyHunters extortion group that it had stolen more than 10 million records and internal corporate data and would leak the information if its demands were not met. Reporting tied the intrusion to a suspected vishing attack that allegedly compromised an employee's Okta single sign-on account and enabled access to ADT's Salesforce environment, matching a broader pattern in which the group targets enterprise SSO accounts and connected SaaS platforms to steal data for extortion.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
After ADT reportedly refused the extortion demand, ShinyHunters published an 11GB archive of allegedly stolen ADT data on its dark web leak site. The leak marked an escalation from the group's earlier threat to release the data unless ADT made contact.
Independent reporting indicated the attackers may have socially engineered an ADT employee to gain access to the company’s Okta environment and then exfiltrated data from Salesforce. The reported intrusion path aligned with a broader ShinyHunters pattern of targeting single sign-on platforms and Salesforce-related data stores.
Independent reporting said Have I Been Pwned added 5.5 million unique email addresses linked to the ADT incident. The listing suggested the breach may be significantly larger than ADT's public description of the stolen data.
As part of its response, ADT directly notified impacted people and offered complimentary identity protection services where appropriate. The company said its investigation was ongoing and it did not believe the incident would materially affect business operations.
ADT disclosed the incident in an SEC Form 8-K filed on 2026-04-24, confirming unauthorized access and theft of limited customer and prospective customer data. The company said it had engaged third-party forensic experts, notified law enforcement, and begun notifying affected individuals.
On 2026-04-23, the ShinyHunters extortion group claimed on its leak site that it had stolen more than 10 million ADT records and internal corporate data. The group threatened to leak the data unless ADT made contact by 2026-04-27.
Following the intrusion, ADT determined that customer and prospective customer personal information was stolen, primarily names, phone numbers, and addresses, with dates of birth and last four digits of Social Security numbers or Tax IDs exposed in a smaller number of cases. ADT said payment information was not accessed and customer security systems were not affected.
ADT detected unauthorized access to certain cloud-based environments on 2026-04-20 and terminated the intrusion. The company activated its incident response plan and began investigating the breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcescworld.com
Open sourcetechjacksolutions.com
Open sourcebankinfosecurity.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcenewsroom.adt.com
Open sourced18rn0p25nwr6d.cloudfront.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.