Eye care company Alcon was listed in a ShinyHunters "pay or leak" extortion campaign after the threat actor allegedly exfiltrated company data and later published it. According to breach reporting, the leaked dataset contains about 218,000 unique email addresses tied largely to business contacts rather than consumer accounts.
The exposed information reportedly consists mostly of corporate B2B contact data, including names, phone numbers, physical addresses, and email addresses. Public breach tracking indicates the data was released after Alcon was targeted for extortion and the demanded payment was either refused or not made, making the incident part of a broader pattern of data-theft-led leak operations by ShinyHunters.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Have I Been Pwned published a breach notice about Alcon identifying the incident as a confirmed data breach notification. The notice described ShinyHunters as the threat actor and summarized the exposed data types and scale.
In August 2026, eye care company Alcon was named in a ShinyHunters "pay or leak" extortion campaign. The threat actor was identified as attempting to coerce payment by threatening to publish stolen data.
ShinyHunters subsequently published data it claimed was sourced from Alcon after payment was refused or not made. The leaked dataset allegedly contained 218,000 unique email addresses plus names, phone numbers, physical addresses, and mostly corporate B2B contact information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.