ADT Inc.
bd_e094ffa4469f3766 · schema v1 · pii pii-v1
Full breach record for ADT Inc. →4 incidents on fileADT LLC reported unauthorized access to its Salesforce database on April 20, 2026, by the threat actor 'Shiny Hunters'. The attackers manipulated an employee via vishing to obtain Okta credentials. The incident affected 331,536 individuals nationwide, including 702 New Hampshire residents. Exposed data included names, emails, phone numbers, addresses, dates of birth, and last four digits of SSNs or Tax IDs. Data was exfiltrated and a ransom demand was issued. ADT contained the breach, notified law enforcement, and is offering credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 20, 2026
Begins
Apr 20, 2026
Discovered
Jul 29, 2026
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitelockbit5bd_9bb50e8a639885802026-08-23 · +25dVerified by operator
- Leak Siteshinyhuntersbd_6a819d19e886ff232026-04-24 · +96dVerified by operator
Regulatory filings (5) · sorted by filing gap
- Texas State AGbd_398dec1b429ee6f92026-07-28 · +1dVerified by operator
- Washington State AGbd_7c187a828ecd79882026-07-28 · +1dVerified
- Oregon State AGbd_a3390e1fa5a8ee7e2026-07-28 · +1dVerified by operator
- Massachusetts State AGbd_aef18852e33a482b2026-07-27 · +2dVerified by operator
Show 1 more filing ↓Show fewer ↑up to 96d gap
- Delaware State AGbd_d1b54352257f31562026-04-24 · +96dVerified by operator
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Apr 24 (DE), last Jul 29 (NH) — a 96-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.