Skip to main content

Company intelligence

Adt cybersecurity incidents and threat signals

adt.com

Adt logo

This company page brings together public reporting currently associated with Adt. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

2

Published signals

currently linked to this company

0

Last 28 days

recent published signals

1

Last 90 days

recent published signals

1

High or critical

confidence classifications

July 22, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Adt. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Adt

Adt logoRansomware
Medium

ADT Data Breach Exposes 5.5 Million Records by ShinyHunters

New Interpol report shows cybercrime surging across Africa Critical Linux zero-day Copy Fail enables root access EU regulator warns on AI-driven cyber risks Social media scams drive $2.1bn in losses in the USA US based home security giant ADT is facing renewed scrutiny after reports that the ShinyHunters extortion group stole the personal information of 5.5 million individuals. The figure was highlighted by data breach notification service Have I Been Pwned following analysis of the stolen dataset. ADT said it detected suspicious activity on 20 April and launched an investigation. According to the company, exposed data included names, phone numbers and addresses, with a smaller number of records also containing dates of birth and the last four digits of Social Security numbers or Tax IDs. ADT stressed that no payment data was accessed and customer security systems were not impacted. The attackers reportedly gained entry through a voice phishing campaign that compromised an employee Okta single sign-on account before moving into connected systems. The incident highlights the growing risk posed by identity-focused attacks targeting SaaS environments. Stronger authentication controls, staff awareness training and continuous monitoring remain critical to defending against modern extortion groups. Cybercrime now represents a growing share of overall crime across Africa, according to INTERPOL’s latest Africa Cyberthreat Assessment Report. Two-thirds of surveyed member countries said cyber-related offences make up a medium-to-high proportion of all crime, rising to more than 30% in Western and Eastern Africa. Online scams remain the most common threat, with phishing attacks widespread across the continent. Ransomware, business email compromise and digital sextortion were also heavily reported, highlighting how financially motivated crime continues to evolve. The report found major capability gaps remain. Ninety percent of countries said law enforcement or prosecution capacity requires significant improvement, while many also cited shortages in training, specialist tools and cyber investigation infrastructure. Despite these challenges, progress is being made. Several nations have strengthened legal frameworks, expanded digital forensics capabilities and invested in dedicated cybercrime units. INTERPOL-led operations have also resulted in more than 1,000 arrests and the disruption of large-scale criminal networks. The findings underline that cybersecurity resilience depends not only on technology, but also on skills, legislation, international cooperation and public-private collaboration. A newly disclosed Linux kernel zero-day vulnerability, tracked as CVE-2026-31431 and nicknamed “Copy Fail”, has raised urgent concerns across the cybersecurity community. The flaw affects Linux distributions using kernel versions released since 2017 and could allow an unprivileged local user to gain full root access. Researchers said the vulnerability can be exploited using a lightweight Python script with no need for race conditions, custom payloads or complex kernel offsets, making exploitation significantly easier than many past privilege escalation flaws. The issue reportedly impacts several major enterprise and cloud platforms, including Ubuntu, Amazon Linux, RHEL and SUSE. Security researchers also warned that the flaw could be used as a container escape technique in Kubernetes environments, potentially allowing compromise of shared host systems. An official patch has now been released, with administrators urged to prioritise updates through their normal distribution channels. Temporary mitigations, including disabling the affected kernel module, have also been recommended. The incident is a reminder that foundational infrastructure remains a prime target, and rapid patch management is essential to reduce exposure when critical vulnerabilities emerge. Europe’s top securities regulator has warned that cyberattacks are becoming faster and more dangerous as artificial intelligence accelerates the threat landscape. Verena Ross, chair of the European Securities and Markets Authority (ESMA), said regulators are closely assessing how advanced AI models could increase the speed and scale of attacks against financial institutions. The warning follows growing industry concern over new AI systems reportedly capable of identifying and exploiting previously unknown vulnerabilities. Financial supervisors across Europe are now reviewing whether firms have the resilience, controls and oversight needed to manage these evolving risks. Ross also stressed that regulators must strengthen their own expertise to effectively supervise both financial entities and the critical third-party technology providers they rely on. Operational resilience and supply chain risk remain key priorities as the sector becomes more dependent on external digital services.

Adt
Adt logoPhishing
High

ADT Data Breach Following ShinyHunters Extortion Threat

ADT confirmed a data breach detected on April 20, 2026, after the ShinyHunters extortion group threatened to leak stolen records. The breach was attributed to a voice phishing (vishing) attack that compromised an employee's Okta single sign-on (SSO) account, used to access the company's Salesforce instance. Compromised information included names, phone numbers, and addresses, with a small percentage including dates of birth and partial SSNs. ShinyHunters claimed theft of more than 10 million records, and Have I Been Pwned later measured the exposed dataset at 5.5 million people.

Adt

FAQ

Questions about Adt cybersecurity reporting

What does the Adt page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Adt.

Does every mention of Adt appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.