ADT says customer data stolen in cyber intrusion
Patch ADT's exposed endpoints and enforce MFA on admin accounts.
Patch ADT's exposed endpoints and enforce MFA on admin accounts.
Summary
ADT, the Florida‑based alarm‑monitoring leader, confirmed that cybercriminals breached its systems on Monday and stole a limited set of customer and prospective customer information. The stolen data included names, phone numbers, addresses, dates of birth, the last four digits of Social Security numbers and tax IDs, but no payment data was compromised. The breach was claimed by the ShinyHunters group, which threatened to leak the 10 million records unless a ransom was paid. ADT has notified all impacted individuals, offered complimentary identity‑protection services, and engaged third‑party cyber experts while law enforcement was alerted. The company has previously reported multiple breaches to the SEC, and ShinyHunters has targeted high‑profile victims such as Rockstar, McGraw Hill, Bumble, Match Group, Canada Goose, the University of Pennsylvania and the European Commission. This incident underscores the growing threat of data‑exfiltration campaigns against security‑focused enterprises.
Key changes
- ADT breached, 10 million records stolen
- Stolen data includes names, phone numbers, addresses, DOB, last four SSN digits, tax IDs
- No payment data was compromised
- ADT notified impacted individuals and offered complimentary identity‑protection services
- ShinyHunters claimed the breach and threatened to leak data for ransom
- ADT reported multiple breaches to the SEC over the past two years
- Law enforcement notified and third‑party cyber experts engaged
- ShinyHunters previously targeted Rockstar, McGraw Hill, Bumble, Match Group, Canada Goose, University of Pennsylvania, European Commission