:

ADT BREACH EXPOSES 5.5M RECORDS IN THIRD 2024 INCIDENT

SECURITY DESK2 MIN READ
WED, APR 29, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Security research group ShinyHunters breached ADT systems and exposed personal data for 5.5 million individuals. The incident marks the third major data breach affecting the home security provider in 2024.

The ShinyHunters extortion group accessed ADT customer information through a breach of the company's systems, according to findings posted on Have I Been Pwned. The compromised dataset includes personal details for 5.5 million people. This marks the latest security incident involving ADT, which disclosed separate data breaches in August 2024 and October 2024. The repeated incidents raise questions about the company's security infrastructure and incident response protocols. ShinyHunters is known for conducting extortion campaigns following data theft operations. The group typically demands payment in exchange for not publicly releasing or selling stolen information. Affected individuals face potential risks including identity theft, phishing attacks, and unauthorized account access. ADT customers exposed in previous 2024 breaches have already experienced compromised credentials and personal information. The data exposure comes as home security companies increasingly become targets for cybercriminals. ADT's repeated breaches within a single year suggest systemic vulnerabilities that require immediate remediation. Have I Been Pwned, operated by security researcher Troy Hunt, aggregates breached datasets to help individuals determine if their personal information has been compromised. The service allows users to check if their email addresses appear in known data breaches. ADT has not issued a public statement regarding this specific incident at the time of reporting. Customers concerned about their data should monitor their accounts for suspicious activity and consider credit monitoring services. The pattern of successive breaches highlights the ongoing challenge organizations face in protecting customer data against determined threat actors.

■ SOURCES

Techmeme

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.

18H AGOIndustry Desk

Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.

18H AGOSecurity Desk

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

18H AGOIndustry Desk

Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.

18H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.