Security research group ShinyHunters breached ADT systems and exposed personal data for 5.5 million individuals. The incident marks the third major data breach affecting the home security provider in 2024.
The ShinyHunters extortion group accessed ADT customer information through a breach of the company's systems, according to findings posted on Have I Been Pwned. The compromised dataset includes personal details for 5.5 million people.
This marks the latest security incident involving ADT, which disclosed separate data breaches in August 2024 and October 2024. The repeated incidents raise questions about the company's security infrastructure and incident response protocols.
ShinyHunters is known for conducting extortion campaigns following data theft operations. The group typically demands payment in exchange for not publicly releasing or selling stolen information.
Affected individuals face potential risks including identity theft, phishing attacks, and unauthorized account access. ADT customers exposed in previous 2024 breaches have already experienced compromised credentials and personal information.
The data exposure comes as home security companies increasingly become targets for cybercriminals. ADT's repeated breaches within a single year suggest systemic vulnerabilities that require immediate remediation.
Have I Been Pwned, operated by security researcher Troy Hunt, aggregates breached datasets to help individuals determine if their personal information has been compromised. The service allows users to check if their email addresses appear in known data breaches.
ADT has not issued a public statement regarding this specific incident at the time of reporting. Customers concerned about their data should monitor their accounts for suspicious activity and consider credit monitoring services.
The pattern of successive breaches highlights the ongoing challenge organizations face in protecting customer data against determined threat actors.
Cody Wilson, creator of the first 3D-printed gun, says he's developed software to bypass government-mandated blocks on 3D printers making firearms. The claim marks the start of an escalating regulatory battle over ghost guns.
Hackers are exploiting critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The flaws allow attackers to forge SAML responses and gain administrator access.
Microsoft's Paint and Photos applications automatically embed invisible GUIDs into locally generated images, according to reverse engineering analysis. The watermarks persist even when files are created entirely offline.
Chinese threat actors are integrating DeepSeek and other open-source AI models into cyberattacks, researchers report. The shift demonstrates how readily available AI tools can amplify hacking capabilities against international targets.