EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-adt-shinyhunters-breach
040/430

File EL-0391HighResolvedData Breach / Extortion with Data Exfiltration

ADT Home Security Data Breach

Also filed as ShinyHunters ADT Hack · ADT Customer Data Leak

The ShinyHunters extortion gang breached home security giant ADT, stealing personal information of approximately 5.5 million individuals. The breach exposed customer data including names, email addresses, phone numbers, and physical addresses linked to their home security systems.

  • #home-security
  • #pii
  • #customer-data
  • #iot-security
  • #extortion
Notoriety8/10
Event
1 Apr 2026
Disclosed
27 Apr 2026
Target
ADT
Actor
ShinyHunters
Scale
5.5M people
Status
Resolved

01Summary

In early April 2026, ShinyHunters gained unauthorized access to ADT's systems and exfiltrated customer records. The stolen data was confirmed by ADT and subsequently listed on Have I Been Pwned with 5.5 million affected accounts. The breach is particularly sensitive due to the nature of ADT's business — home security — where customer address data directly correlates to the location of alarm systems and security vulnerabilities.

02Background

ADT is the largest home security company in the United States, providing monitoring services for millions of homes and businesses. Breaches of home security companies carry unique risks, as exposed address and alarm system data can potentially be used to facilitate physical break-ins.

03Key revelations

  1. 01Home security companies hold uniquely sensitive data linking customer identities to physical addresses and alarm system details.
  2. 02ShinyHunters successfully targeted critical home infrastructure providers.

04Technical analysis

The attack followed ShinyHunters' established methodology, likely involving social engineering (vishing) to compromise employee credentials and access customer databases.

Attack vector
Social engineering / Credential compromise
Attack method
Data exfiltration and extortion
Initial access
Social engineering (likely vishing)
Exfiltration
Bulk data extraction

05Threat actor

ShinyHunters is a prolific cybercriminal/extortion group known for targeting large corporations and high-value datasets for financial gain through data extortion.

Aliases

  • SH
  • Scattered LAPSUS$ Hunters

Attribution sources

  • ShinyHunters leak site
  • ADT statements
  • BleepingComputer
  • Have I Been Pwned

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • PII
  • Names
  • Email addresses
  • Phone numbers
  • Physical addresses
  • Account information

08Financial damage

Increased risk of physical security compromise for customers; regulatory fines and class-action lawsuits expected.

09Timeline

  1. 2026-04-01Approximate date of initial breach.
  2. 2026-04-24ShinyHunters threatens to leak ADT data.
  3. 2026-04-27ADT confirms breach; HIBP lists 5.5M affected accounts.

10Reaction and fallout

Public reaction

Heightened concern over physical security risks from exposed home address and alarm system data.

11Legal

Ongoing investigations; class-action lawsuits anticipated.

Civil lawsuits

  • Anticipated class-action lawsuits related to physical security risks

12Significance and legacy

Significance

Demonstrates the unique physical security risks of data breaches at home security providers, where exposed data can directly compromise customer safety.

Legacy

Highlights the need for enhanced security standards in the home security and IoT safety industry.

13Disclosure and media

Authentication
ShinyHunters leak site and ADT official confirmation

Publishing organisations

  • BleepingComputer
  • Have I Been Pwned

14Related files

Related events

  • 2026-charter-communications-shinyhunters-breach
  • 2026-carnival-cruise-shinyhunters-breach

15Field notes

  1. 01ADT monitors over 6 million homes and businesses across the United States.
  2. 02The breach exposed physical addresses linked to active home security systems.

16Resolution

ADT confirmed the breach and began notifying affected customers.

17Sources

Official documents

  • ADT data breach notification

References

  1. [1]BleepingComputer: Home security giant ADT data breach affects 5.5 million people
  2. [2]BleepingComputer: ADT confirms data breach after ShinyHunters leak threat
Fact sheetEL-0391

Dates

Event
1 Apr 2026
Started
1 Apr 2026
Discovered
1 Apr 2026
Disclosed
27 Apr 2026
Ongoing
No

Target

Organisation
ADT Inc.
Type
Technology Company
Sector
Home Security
Country
United States

Actor

Name
ShinyHunters
Type
Criminal Gang
Motivation
Financial gain through data extortion.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
5,500,000
Records
5,500,000
Sensitivity
High
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Likely (standard for ShinyHunters)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.