Breaches · 141 days ago
ADT’s intrusion matters because the stolen data can be used for identity abuse even if the company’s alarm hardware and payment systems were untouched. The standard response misses that names, contact details, dates of birth, and partial SSNs or tax IDs are enough to fuel account takeover, fraud, and targeted social engineering.
ADT says the breach exposed a limited set of customer and prospective-customer records, including names, phone numbers, addresses, dates of birth, and the last four digits of Social Security numbers and tax IDs. The company says no payment data was taken and customer security systems were not compromised, but a cybercriminal group later claimed 10 million records and threatened to leak them unless paid.
The gap between ADT’s disclosure and the ransom claim leaves open the possibility of broader exposure than the company has confirmed. Even if the breach stays limited, the data type creates long-lived identity risk for affected people.
3 sources covering this story
Burglar alarm biz gets burgled, ShinyHunters pursues ransom
: Security giant says attackers grabbed 'limited set' of data.
ADT confirms data breach after ShinyHunters leak threat
Home security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.
The Record from Recorded Future
ADT says customer data stolen in cyber intrusion
The home security company ADT said cybercriminals breached company systems on Monday and stole a “limited set” of customer and prospective customer information.
Part of the PlainSec briefing for 2026-04-27