Eastman Kodak confirmed it is investigating a cybersecurity breach after an unauthorized third party briefly accessed a limited amount of company data. The company said it has engaged external cybersecurity experts and is coordinating with law enforcement, while maintaining that there is no threat to its systems or ongoing operations and that no operational disruption has been reported.
The confirmation followed claims by the ShinyHunters extortion group, which said it stole more than 2.2 million records containing customer PII and internal corporate data. Kodak has not verified the full scope of those claims, has not disclosed what categories of customer information may have been affected, and no proof samples had been published, but the group threatened to leak the allegedly exfiltrated data and potentially carry out additional disruptive activity if the company did not respond by June 18, 2026.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
ShinyHunters threatened to leak the allegedly exfiltrated Kodak data and potentially carry out additional disruptive activity if Kodak did not respond. The deadline cited in the reporting was June 18, 2026.
Kodak confirmed that an unauthorized third party briefly accessed a limited amount of company data and said it is investigating the incident. The company stated it engaged external cybersecurity experts, is working with law enforcement, and is confident there is no threat to its systems or operations.
ShinyHunters claimed on its leak site that it had stolen more than 2.2 million Kodak records containing customer PII and internal corporate data. The group did not publish proof samples, according to the reporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcesecurityweek.com
Open sourcexakep.ru
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcesecuritymagazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.