ADT Inc.
bd_9bb50e8a63988580 · schema v1 · pii pii-v2
Full breach record for ADT Inc. →4 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Lockbit5 on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Sanctions caution: Lockbit5 carries US sanctions exposure — OFAC has designated the group or its operators. Public reporting is permitted (informational-materials exemption, 50 U.S.C. § 1702(b)(3)) — but any payment or material support may violate sanctions. Consult counsel before engaging.
Source: Ransomware.live
Post text · scraped from the leak site
ADT is a security company that offers security systems, cameras, alarms ad home automation services....
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Aug 23, 2026
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteshinyhuntersbd_6a819d19e886ff232026-04-24 · +121dVerified by operator
Regulatory filings (6) · sorted by filing gap
- New Hampshire State AGShiny Huntersbd_e094ffa4469f37662026-07-29 · +25dVerified by operator
- Texas State AGbd_398dec1b429ee6f92026-07-28 · +26dVerified by operator
- Washington State AGbd_7c187a828ecd79882026-07-28 · +26dVerified
- Oregon State AGbd_a3390e1fa5a8ee7e2026-07-28 · +26dVerified by operator
Show 2 more filings ↓Show fewer ↑up to 121d gap
- Massachusetts State AGbd_aef18852e33a482b2026-07-27 · +27dVerified by operator
- Delaware State AGbd_d1b54352257f31562026-04-24 · +121dVerified by operator
Filing propagation · 7 filings · 6 states
View merged incident ↗Pattern: first filing Apr 24 (DE), last Aug 23 — a 121-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
lockbit5
According to ransomware.live, LockBit 5.0 ("ChuongDong") emerged in September 2025 as the group's resurgence following the February 2024 law enforcement takedown, introducing cross-platform payloads targeting Windows, Linux, and VMware ESXi with enhanced evasion capabilities and continuing the RaaS affiliate model of its predecessors.