Skip to main content
Back to overview
High

ADT Data Breach Following ShinyHunters Extortion Threat

ADT confirmed a data breach detected on April 20, 2026, after the ShinyHunters extortion group threatened to leak stolen records.

Key points

  • Data breach detected on April 20, 2026.
  • ShinyHunters extortion group claimed responsibility.
  • Breach caused by a vishing attack compromising an employee's Okta SSO account.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Social, Error activity

03

Potential impact

Data Exposure

Confidentiality

Published
Apr 20, 2026
Updated
Jul 3, 2026
Confidence
High
Evidence
12 sources

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Social, Error activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: possible insider or internal misuse

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

AdtData DisclosureExtortion Threat ADTShinyHuntersOktaSSOSalesforceCompromisedSSNs. ShinyHuntersHave I Been Pwned

Quick context

Questions about this signal

What happened in this signal?

ADT confirmed a data breach detected on April 20, 2026, after the ShinyHunters extortion group threatened to leak stolen records. The breach was attributed to a voice phishing (vishing) attack that compromised an employee's Okta single sign-on (SSO) account, used to access the company's Salesforce instance. Compromised information included names, phone numbers, and addresses, with a small percentage including dates of birth and partial SSNs. ShinyHunters claimed theft of more than 10 million records, and Have I Been Pwned later measured the exposed dataset at 5.5 million people.

When was this signal reported?

Shadow Tier lists Apr 20, 2026 as the signal date.

Which organization is connected to this signal?

Adt is the organization connected to this public signal.

Explore Adt
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence