Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

816+ Articles
121+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Home Security Giant ADT Data Breach Affects 5.5 Million People
Home Security Giant ADT Data Breach Affects 5.5 Million People
NEWS

Home Security Giant ADT Data Breach Affects 5.5 Million People

The ShinyHunters extortion group stole the personal information of 5.5 million individuals after breaching the systems of home security giant ADT earlier in April 2026. Have I Been Pwned confirms the breach, exposing names, emails, phone numbers, and addresses.

Dylan H.

News Desk

April 27, 2026
4 min read

ADT Breached by ShinyHunters — 5.5 Million Customers Exposed

Home security giant ADT has confirmed a data breach affecting 5.5 million individuals, after the notorious ShinyHunters extortion group stole personal customer information earlier this month. The compromise was independently confirmed by breach notification service Have I Been Pwned (HIBP), which added the dataset to its database.

This marks ShinyHunters' continued pattern of high-profile corporate breaches in 2026, following similar attacks against Canada Goose, Telus Digital, Infinite Campus, and others earlier in the year.


What Was Stolen

ADT's breach notification and HIBP data confirm that the exposed records include a range of customer personal data:

Data CategoryExposed
Full namesYes
Email addressesYes
Phone numbersYes
Physical addressesYes
Account status informationYes
Payment card detailsNot confirmed
Passwords / credentialsNot confirmed

The 5.5 million affected individuals include ADT residential security system customers across the United States.


ShinyHunters: Prolific Data Extortion Threat Actor

ShinyHunters is one of the most active data breach and extortion groups operating in 2025–2026. The group is known for:

  • Targeting large enterprises with exposed API credentials or third-party integrations
  • Extracting large customer databases and offering them for sale on criminal forums
  • Publicly naming victims and threatening exposure if ransom demands are not met
  • Operating under a "hack, extort, leak" model — different from encryption-focused ransomware groups

The group's 2026 victim list has grown significantly, with ADT joining a roster of high-profile breaches that together have exposed data on tens of millions of individuals.


Timeline

DateEvent
Early April 2026ShinyHunters breaches ADT network
April 24, 2026ADT discloses breach to SEC; ShinyHunters posts leak threat
April 25, 2026ADT confirms customer data stolen
April 27, 2026HIBP adds 5.5M records; BleepingComputer reports full scope

Impact Assessment

The ADT breach carries significant downstream risk for affected customers:

Phishing and Social Engineering

With names, emails, phone numbers, and addresses, threat actors can craft highly convincing phishing emails and vishing (voice phishing) calls. Customers claiming to be ADT support with "urgent security alerts" should be treated with suspicion.

Physical Security Risk

ADT customers' home addresses, combined with their home security system enrollment status, could theoretically be used to identify properties protected by ADT — and by extension, the types of alarms and monitoring in place.

Identity Theft

The combination of names, emails, phone numbers, and addresses is sufficient for identity theft attempts, fraudulent account openings, and SIM-swap attacks.


What Affected Users Should Do

  1. Check Have I Been Pwned — visit haveibeenpwned.com and search your email address to confirm if you are in the dataset
  2. Be alert for phishing — do not trust unsolicited calls or emails claiming to be from ADT; contact ADT only through verified phone numbers or the official website
  3. Enable two-factor authentication on your ADT online account and any accounts sharing the same email
  4. Freeze your credit if you are concerned about identity theft — contact Equifax, Experian, and TransUnion
  5. Monitor financial accounts for unusual activity
  6. Watch for SIM-swap attempts — contact your mobile carrier to add a PIN or verbal password to your account

ADT's Response

ADT has stated that it is notifying affected customers directly and has taken steps to contain the breach. The company confirmed that the intrusion affected "certain corporate IT systems" but has not publicly detailed the attack vector.

As of April 27, 2026, ADT has not confirmed whether payment card data or credential hashes were included in the stolen dataset.


Key Takeaways

  • 5.5 million ADT customers had personal information stolen by ShinyHunters in April 2026
  • Have I Been Pwned has added the dataset — affected users can check their exposure now
  • ShinyHunters continues a prolific 2026 run of high-profile data extortion attacks
  • The breach exposes customers to phishing, vishing, and identity theft risks
  • ADT customers should enable 2FA, monitor accounts, and be alert to social engineering

Sources

  • Home Security Giant ADT Data Breach Affects 5.5 Million People — BleepingComputer
  • Have I Been Pwned
  • ADT Confirms Data Breach — April 25, 2026
#Data Breach#ADT#ShinyHunters#Have I Been Pwned#Personal Data#Home Security

Related Articles

ADT Says Customer Data Stolen in Cyber Intrusion

Home security giant ADT confirmed that cybercriminals breached its systems and stole a limited set of customer and prospective customer information. The...

3 min read

ADT Confirms Data Breach After ShinyHunters Leak Threat

Home security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to publish stolen data unless a ransom is paid,...

5 min read

Next.js Creator Vercel Hacked

Vercel confirmed suffering a breach after a hacker claiming to be part of ShinyHunters offered to sell stolen data for $2 million, affecting the company...

3 min read
Back to all News