Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Windows Tipps & SecurityDave Plummer Has Made the Task Manager of Your Dreams(21.09.2026 um 21:20 Uhr)
Sichere ProgrammierungSubqueries and CTEs: Asking a Question Inside a Question(21.09.2026 um 21:00 Uhr)
Sichere ProgrammierungTVL Trend Analysis & Liquidity Risk Assessment: Lido(21.09.2026 um 21:00 Uhr)
Sichere ProgrammierungReact is Officially Dead in 2026 (Thanks to AI)(21.09.2026 um 21:01 Uhr)
Sichere ProgrammierungUsing SHA256 to Build Trustworthy Data Portals in Brazil(21.09.2026 um 21:01 Uhr)
Sichere Programmierung🚀 I reached 1,001 views on DEV!(21.09.2026 um 21:03 Uhr)
Sichere ProgrammierungReact Mental Models 2(21.09.2026 um 21:05 Uhr)
Sichere ProgrammierungAustralian RAM and SSD prices climb as stock tightens(21.09.2026 um 21:09 Uhr)
Windows Tipps & SecurityDave Plummer Has Made the Task Manager of Your Dreams(21.09.2026 um 21:20 Uhr)
Sichere ProgrammierungSubqueries and CTEs: Asking a Question Inside a Question(21.09.2026 um 21:00 Uhr)
Sichere ProgrammierungTVL Trend Analysis & Liquidity Risk Assessment: Lido(21.09.2026 um 21:00 Uhr)
Sichere ProgrammierungReact is Officially Dead in 2026 (Thanks to AI)(21.09.2026 um 21:01 Uhr)
Sichere ProgrammierungUsing SHA256 to Build Trustworthy Data Portals in Brazil(21.09.2026 um 21:01 Uhr)
Sichere Programmierung🚀 I reached 1,001 views on DEV!(21.09.2026 um 21:03 Uhr)
Sichere ProgrammierungReact Mental Models 2(21.09.2026 um 21:05 Uhr)
Sichere ProgrammierungAustralian RAM and SSD prices climb as stock tightens(21.09.2026 um 21:09 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

ADT Confirms Data Breach: ShinyHunters Claim 10 Million Records Stolen

What Happened On April 23, 2026, the ShinyHunters extortion group posted on a leak forum what they claim to be approximately 10 million customer records belonging to ADT — the largest residential security provider in the United States. A…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




What Happened



On April 23, 2026, the ShinyHunters extortion group posted on a leak forum what they claim to be approximately 10 million customer records belonging to ADT — the largest residential security provider in the United States. ADT publicly confirmed the intrusion within 24 hours of the leak appearing, telling BleepingComputer that an unauthorized third party had "obtained certain customer information" and that the company's security team had since contained the access.



The company is now contacting affected customers and offering complimentary credit monitoring, but the leaked sample published by the attackers — names, email addresses, home addresses, and references to active service contracts — has already been independently confirmed by multiple security outlets including CyberInsider and UndercodeNews. Several customers contacted by reporters were able to verify their own records in the leaked sample.






Technical Analysis: How ShinyHunters Likely Got In



ADT has not publicly disclosed the initial access vector, and the company's official statement is restricted to language about "unauthorized access to a portion of our environment" without specifying whether the breach hit a customer-facing application, an internal admin panel, or a third-party SaaS provider. That ambiguity is itself a signal: in our experience auditing companies that disclose breaches with this exact phrasing, the most common root causes are credential reuse against an admin login, an exposed API endpoint without rate limiting, or compromise of a marketing or CRM tool that holds a customer mirror.



ShinyHunters' historical playbook reinforces those hypotheses. The group has spent the last 24 months running a consistent operation against cloud-hosted data warehouses and SaaS admin panels, taking advantage of customer accounts that lacked multi-factor authentication. Threat-research analysis of the ADT incident notes that the same group has previously compromised dozens of large enterprises throughout 2025 and early 2026 — Ticketmaster, Santander, AT&T, and a long list of less prominent victims — using nothing more sophisticated than valid credentials harvested from infostealer logs and a willingness to go straight to public extortion when the victim refuses to pay.



If ADT followed the pattern of those earlier victims, the kill chain looks like this: an employee or contractor's workstation was infected with a generic infostealer at some point in 2025; that infostealer captured a session cookie or credential to a corporate SaaS (most commonly a data warehouse, CRM, or ticketing system); the credential ended up for sale on Russian Market or a comparable broker; ShinyHunters bought it for low three-digit dollars; they logged in, ran SELECT * against the customer table, exfiltrated, and then opened the extortion conversation on TOX or a private channel before going public when negotiations stalled.






Who's Affected and What Was Exposed



The leaked sample published by ShinyHunters indicates the following fields per record: full name, email address, physical home address, phone number, and service plan reference. Notably, the leaked data so far does not appear to include payment card numbers, social security numbers, or alarm system credentials — which would be far more dangerous and which ADT has explicitly said are not affected.



That said, the combination of name + home address + active home-security service contract is itself an unusually sensitive dataset. ADT's customer base skews toward homeowners specifically because they have something to protect: jewelry, electronics, sometimes weapons, occasionally high-net-worth occupants. A motivated burglary crew with this list has a directly actionable target file. The downstream risk here is not identity theft in the traditional sense — it's physical targeting, especially for the subset of customers who installed ADT precisely because they were already concerned about being targeted.



For the ShinyHunters operators themselves, the value in this dataset is not the fields per se but the leverage. Public extortion of a brand whose entire value proposition is "keeping your home safe" is exactly the kind of headline the group has cultivated for two years.






How to Protect Yourself if You're an ADT Customer




  1. Change your ADT account password today, even though the leak does not appear to include passwords. If you have reused that password anywhere else, change it everywhere — and switch to a password manager so you don't have to do this exercise again next time.


  2. Enable multi-factor authentication on the ADT customer portal and on any account where your ADT email is the recovery address. The fact that ShinyHunters has now confirmed they have your email means it is on every targeted phishing list for the foreseeable future.


  3. Be skeptical of any communication referencing your ADT service in the next 90 days. "Your ADT system needs an urgent firmware update — click here to authorize it" is the obvious phishing pretext, and it will be running. ADT will not ask you to authorize anything via email link; if you receive something that looks important, navigate to adt.com directly and log in.


  4. Check whether your home address appears on people-search and data-broker sites. If it does, request removal — California, Colorado, and a growing list of states require brokers to honor opt-outs. The combination of a verified home address on a public broker plus a known ADT service contract is a particularly clean target for harassment or burglary.


  5. If you are a high-profile or high-net-worth customer, treat this as a strong nudge to audit your physical security posture independently — alarm code rotation, neighbor awareness, package handling. The breach itself does not give attackers your alarm code, but it tells them you have one worth bypassing.







The Sable Angle



What stands out about the ADT incident, and almost every ShinyHunters incident before it, is how unsophisticated the attack pattern is relative to the size of the prize. There is no zero-day. There is no nation-state implant. There is a stolen session cookie or a reused password and an admin endpoint that did not enforce MFA. The breach is the predictable consequence of a known control gap that nobody owned closing.



In the offensive engagements we run at Sable, we surface this exact category of finding inside roughly 80% of mid-market and enterprise environments we test. The pattern is so consistent that we built our standard methodology around it: prove that a single leaked credential, given current MFA coverage and current admin-endpoint exposure, is sufficient to reach the customer or financial dataset. We do that work before ShinyHunters does, and we hand the customer a remediation path that is short, specific, and ordered by exploitability — not by CVSS theater. If you want to know whether an attacker with a single $50 credential could repeat the ADT outcome on your environment, our research on third-party credential exposure is a reasonable place to start, and the conversation about a focused engagement is the next step.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten ADT Confirms Data Breach: ShinyHunters Claim 10 Million Records Stolen

Thematisch verwandte Begriffe: Confirms, Data, Breach, ShinyHunters · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94494 | jshERP through 3.6 contains a tenant isolation bypass vulnerability that…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick