DisclosureLens
Social EngineeringTechnologyProfessional ServicesInformationVishingStolen CredentialsRansomwareShiny HuntersData ExfiltratedRansom DemandedCustomer Data InvolvedMulti-Stage ChainIdentity (basic)Government IDCriticalContained

ADT Inc.

bd_e094ffa4469f3766 · schema v1 · pii pii-v1

Severity

Critical

Discovered

Apr 20, 2026

Filed

Jul 29, 2026

To disclose

14 weeks

Affected · nationwide

331,536702 in this filing

Linked

8 filings

Confidence

66%
Full breach record for ADT Inc.4 incidents on file

ADT LLC reported unauthorized access to its Salesforce database on April 20, 2026, by the threat actor 'Shiny Hunters'. The attackers manipulated an employee via vishing to obtain Okta credentials. The incident affected 331,536 individuals nationwide, including 702 New Hampshire residents. Exposed data included names, emails, phone numbers, addresses, dates of birth, and last four digits of SSNs or Tax IDs. Data was exfiltrated and a ransom demand was issued. ADT contained the breach, notified law enforcement, and is offering credit monitoring services.

Leak gap clock Leak >90d14 weeks discovery → filing

Incident timeline

discovery → filing · 14 weeks / 100 days

Apr 20, 2026

Begins

Apr 20, 2026

Discovered

Jul 29, 2026

Filed

vs. sector median

4 wks faster

This filing is one of 8 about the same incident.View merged incident
A leak claim by shinyhunters about this victim predates this filing by 95 days.View originating leak claim

Linked disclosures

Why this link?

Ransomware claims (2)

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 96d gap

Filing propagation · 6 filings · 6 states

View merged incident ↗
Delaware State AGApr 24 · first
New Hampshire State AG+96d · this page

Pattern: first filing Apr 24 (DE), last Jul 29 (NH) — a 96-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.