Skip to main content
Back to overview
Medium

ADT Data Breach Exposes 5.5 Million Records by ShinyHunters

New Interpol report shows cybercrime surging across Africa Critical Linux zero-day Copy Fail enables root access EU regulator warns on AI-driven cyber risks Social media scams drive $2.1bn in losses in the USA US based…

Key points

  • Disclosure/reports on May 1, 2026.
  • Detected suspicious activity on April 20, 2026.
  • Affected 5.5 million individuals.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Social, Hacking activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
May 1, 2026
Updated
Jul 22, 2026
Confidence
Medium
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Social, Hacking activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: possible insider or internal misuse

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

AdtData DisclosureShinyHunters New InterpolAfrica Critical LinuxCopy FailAI-drivenSocialUSA USADTShinyHunters

Quick context

Questions about this signal

What happened in this signal?

New Interpol report shows cybercrime surging across Africa Critical Linux zero-day Copy Fail enables root access EU regulator warns on AI-driven cyber risks Social media scams drive $2.1bn in losses in the USA US based home security giant ADT is facing renewed scrutiny after reports that the ShinyHunters extortion group stole the personal information of 5.5 million individuals. The figure was highlighted by data breach notification service Have I Been Pwned following analysis of the stolen dataset. ADT said it detected suspicious activity on 20 April and launched an investigation. According to the company, exposed data included names, phone numbers and addresses, with a smaller number of records also containing dates of birth and the last four digits of Social Security numbers or Tax IDs. ADT stressed that no payment data was accessed and customer security systems were not impacted. The attackers reportedly gained entry through a voice phishing campaign that compromised an employee Okta single sign-on account before moving into connected systems. The incident highlights the growing risk posed by identity-focused attacks targeting SaaS environments. Stronger authentication controls, staff awareness training and continuous monitoring remain critical to defending against modern extortion groups. Cybercrime now represents a growing share of overall crime across Africa, according to INTERPOL’s latest Africa Cyberthreat Assessment Report. Two-thirds of surveyed member countries said cyber-related offences make up a medium-to-high proportion of all crime, rising to more than 30% in Western and Eastern Africa. Online scams remain the most common threat, with phishing attacks widespread across the continent. Ransomware, business email compromise and digital sextortion were also heavily reported, highlighting how financially motivated crime continues to evolve. The report found major capability gaps remain. Ninety percent of countries said law enforcement or prosecution capacity requires significant improvement, while many also cited shortages in training, specialist tools and cyber investigation infrastructure. Despite these challenges, progress is being made. Several nations have strengthened legal frameworks, expanded digital forensics capabilities and invested in dedicated cybercrime units. INTERPOL-led operations have also resulted in more than 1,000 arrests and the disruption of large-scale criminal networks. The findings underline that cybersecurity resilience depends not only on technology, but also on skills, legislation, international cooperation and public-private collaboration. A newly disclosed Linux kernel zero-day vulnerability, tracked as CVE-2026-31431 and nicknamed “Copy Fail”, has raised urgent concerns across the cybersecurity community. The flaw affects Linux distributions using kernel versions released since 2017 and could allow an unprivileged local user to gain full root access. Researchers said the vulnerability can be exploited using a lightweight Python script with no need for race conditions, custom payloads or complex kernel offsets, making exploitation significantly easier than many past privilege escalation flaws. The issue reportedly impacts several major enterprise and cloud platforms, including Ubuntu, Amazon Linux, RHEL and SUSE. Security researchers also warned that the flaw could be used as a container escape technique in Kubernetes environments, potentially allowing compromise of shared host systems. An official patch has now been released, with administrators urged to prioritise updates through their normal distribution channels. Temporary mitigations, including disabling the affected kernel module, have also been recommended. The incident is a reminder that foundational infrastructure remains a prime target, and rapid patch management is essential to reduce exposure when critical vulnerabilities emerge. Europe’s top securities regulator has warned that cyberattacks are becoming faster and more dangerous as artificial intelligence accelerates the threat landscape. Verena Ross, chair of the European Securities and Markets Authority (ESMA), said regulators are closely assessing how advanced AI models could increase the speed and scale of attacks against financial institutions. The warning follows growing industry concern over new AI systems reportedly capable of identifying and exploiting previously unknown vulnerabilities. Financial supervisors across Europe are now reviewing whether firms have the resilience, controls and oversight needed to manage these evolving risks. Ross also stressed that regulators must strengthen their own expertise to effectively supervise both financial entities and the critical third-party technology providers they rely on. Operational resilience and supply chain risk remain key priorities as the sector becomes more dependent on external digital services.

When was this signal reported?

Shadow Tier lists May 1, 2026 as the signal date.

Which organization is connected to this signal?

Adt is the organization connected to this public signal.

Explore Adt
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence