What Happened
On April 23, 2026, the ShinyHunters extortion group posted on a leak forum what they claim to be approximately 10 million customer records belonging to ADT — the largest residential security provider in the United States. ADT publicly confirmed the intrusion within 24 hours of the leak appearing, telling BleepingComputer that an unauthorized third party had "obtained certain customer information" and that the company's security team had since contained the access.
The company is now contacting affected customers and offering complimentary credit monitoring, but the leaked sample published by the attackers — names, email addresses, home addresses, and references to active service contracts — has already been independently confirmed by multiple security outlets including CyberInsider and UndercodeNews. Several customers contacted by reporters were able to verify their own records in the leaked sample.
Technical Analysis: How ShinyHunters Likely Got In
ADT has not publicly disclosed the initial access vector, and the company's official statement is restricted to language about "unauthorized access to a portion of our environment" without specifying whether the breach hit a customer-facing application, an internal admin panel, or a third-party SaaS provider. That ambiguity is itself a signal: in our experience auditing companies that disclose breaches with this exact phrasing, the most common root causes are credential reuse against an admin login, an exposed API endpoint without rate limiting, or compromise of a marketing or CRM tool that holds a customer mirror.








