CSIDB logo
Incident

ADT Inc.

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-16 02:02

Linked entities

Victim
ADT Inc.
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Apr 2026
Discovered
Apr 2026
Disclosed
Apr 2026
Resolved
Pending

Summary

ADT Inc. confirmed a data breach after detecting unauthorized access to a limited set of customer and prospective customer data, which the company said was traced to a voice phishing attack that compromised an employee's single sign‑on account and allowed access to its Salesforce system. The exposed information included names, phone numbers, addresses, and in a small subset dates of birth and the last four digits of Social Security numbers, while no payment card data or security system functionality was affected. The hacker group ShinyHunters claimed responsibility and alleged theft of over ten million records, a figure the company has not verified, and a national class‑action law firm has opened an investigation into potential claims arising from the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 20, 2026, ADT's cybersecurity systems detected unauthorized access to a limited set of customer and prospective customer data, prompting the activation of the company's response protocols. The intrusion was terminated immediately, a forensic investigation was launched with leading third‑party cybersecurity experts, and law enforcement was notified. ShinyHunters, a known cybercrime group, claimed responsibility for the breach and told BleepingComputer that they used a voice phishing (vishing) attack to compromise an employee's Okta single sign‑on account. According to the group, this access enabled them to exfiltrate data from ADT's Salesforce system, although ADT has not publicly confirmed the specific attack method.

The investigation confirmed that the compromised information consisted of names, phone numbers, and addresses, with a small percentage of records also containing dates of birth and the last four digits of Social Security numbers or Tax IDs. No payment information such as bank account or credit card details was accessed, and ADT stated that customer security systems were not affected or compromised in any way. This incident follows earlier disclosures by ADT of data breaches in August and October 2024 that exposed customer and employee information. ADT describes itself as the nation's largest home security company, providing monitored and self‑install systems, smart home features, and fire safety services from its headquarters in Boca Raton, Florida.

Because the exposed data includes personal identifiers, individuals whose information was involved may face an increased risk of identity theft and fraud, including the potential for scams that use the stolen details to appear legitimate. Edelson Lechtzin LLP, a national class action law firm, announced on April 27, 2026 that it is investigating data privacy claims arising from the ADT breach and is offering free case evaluations to affected individuals. The firm stated that it will evaluate potential claims at no cost and is considering a class action to pursue legal remedies on behalf of those whose sensitive personal data may have been compromised. ADT has notified law enforcement and continues to cooperate with the forensic investigation and any ensuing legal proceedings.

Sources

Sources available to members: 2 sources.

CSIDB