TL;DR: ShinyHunters breached ADT (the largest home security company in the United States) by voice-phishing a single employee on April 20, 2026. That phone call gave them access to ADT's Okta single sign-on, which opened the door to Salesforce. ShinyHunters claims they grabbed 10 million customer records containing names, addresses, phone numbers, and in some cases dates of birth and partial Social Security numbers. They gave ADT until April 27 to pay a ransom or face a public data dump. ADT confirmed the breach in an SEC 8-K filing on April 24 but says no payment data or home security systems were compromised. This is ADT's second breach in less than two years. And it's part of a ShinyHunters vishing campaign that's hit dozens of companies through the exact same SSO playbook.
One Phone Call, 10 Million Records
On April 20, 2026, ADT detected unauthorized access to its systems. By the time they shut it down, the damage was done [1].
Here's how ShinyHunters pulled it off, according to reporting from BleepingComputer and CyberInsider [1][2]:
- Vishing. Someone from ShinyHunters called an ADT employee and social-engineered them into handing over their Okta SSO credentials. One phone call. That's all it took.
- Okta SSO access. With a single employee's Okta login, ShinyHunters had the keys to ADT's connected SaaS applications.
- Salesforce raid. They went straight to Salesforce (where ADT stores customer relationship data) and started pulling records.
- 10 million records out. ShinyHunters claims they exfiltrated over 10 million records containing personally identifiable information and internal corporate data.
ADT's SEC filing says the stolen data includes names, phone numbers, and physical addresses. A smaller subset includes dates of birth and the last four digits of Social Security numbers or Tax IDs [1][3].
ADT says no payment information (no bank accounts, no credit cards) was accessed. They also say customer security systems were not affected or compromised [3].
Cold comfort when someone has your name, home address, phone number, and partial SSN. Especially when that someone is a criminal group with a track record of selling stolen data.
The April 27 Deadline
ShinyHunters didn't just steal the data and disappear. They posted the breach publicly and issued an ultimatum [1][2]:
"This is a final warning to reach out by 27 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way."
April 27. That's today.
If ADT didn't pay (and nothing public suggests they did) expect 10 million records to start circulating on dark web forums and Telegram channels in the coming hours or days.
ShinyHunters has followed through on these threats before. They dumped data from Vercel, Kemper Corporation, and Ameriprise Financial when companies didn't pay. There's no reason to think ADT will be different.
The Vishing Playbook
This wasn't some novel zero-day exploit. ShinyHunters called someone on the phone and talked their way in.
It's the same attack they've used against dozens of companies since late 2025. According to a Google Cloud threat intelligence report, ShinyHunters has been running widespread vishing campaigns targeting employees and business process outsourcing (BPO) agents' SSO accounts across three major platforms [4]:
- Microsoft Entra (formerly Azure AD)
- Okta
- Google Workspace
Once they're inside the SSO, they pivot to connected SaaS apps (Salesforce, Microsoft 365, Google Workspace, SharePoint) and vacuum up data. The SSO is the front door. Everything behind it is open.
ADT isn't an outlier. They're just the latest company to learn that their entire security posture depended on whether one employee could spot a social engineering call. That employee couldn't. Most can't.
ADT's Second Breach in Two Years
In August 2024, ADT disclosed a separate breach after a threat actor using the handle "netnsher" advertised stolen ADT customer data on a hacking forum. That breach exposed over 30,000 records containing customer email addresses, phone numbers, physical addresses, and order information [5].
ADT filed an SEC 8-K for that one too. Notified affected customers. Offered credit monitoring. Said they'd strengthen their security.
Twenty months later, a different group called an employee, got their Okta password, and walked out with 10 million records.
Whatever ADT did to "strengthen security" after the 2024 breach, it apparently didn't include phishing-resistant MFA on employee SSO accounts. Or if it did, one phone call was enough to bypass it.
The Company That Sells Security Can't Secure Itself
ADT has been selling security since 1874. They monitor over 6 million homes and businesses across the United States. Their entire brand promise is: we'll protect you.
But ADT's digital security just got beaten by a phone call.
This isn't about whether your ADT alarm still works. The company says home security systems weren't affected. Fine. But ADT collects massive amounts of personal data to run its business: names, addresses, phone numbers, account details, service history. That data is now in criminal hands.
If you trust a company to monitor your home, you'd expect them to monitor their own networks at least as carefully. ADT detected the intrusion on April 20 and terminated it the same day, which is better than Ameriprise's 16-day blind spot. But the question isn't how fast they caught it. The question is how a vishing call got past their defenses in the first place.
What ADT Customers Should Do
- Assume your data is compromised. ADT hasn't disclosed how many of its 6+ million customers are in the 10 million records ShinyHunters claims. Until ADT clarifies, assume you're affected.
- Watch for targeted scams. Criminals now have names matched with home addresses. Expect phishing calls and texts posing as ADT technicians or offering "security upgrades." ADT will never ask for your account password by phone, email, or text.
- Freeze your credit if your SSN was exposed. ADT says only a small percentage of records include partial SSNs. If you get a notification letter saying yours was included, freeze your credit at all three bureaus immediately. It's free.
- Check for ADT's notification. ADT says they're directly notifying affected customers. Keep an eye on your mail and email for a breach notification letter.
- Change your ADT account password. If you have an online ADT account, change your password now. Use a unique password you don't reuse anywhere else.
- Don't trust caller ID. Anyone with your name and address can spoof a call that looks like it's from ADT. If someone calls about your security system, hang up and call ADT's official number yourself.
ShinyHunters Isn't Slowing Down
ADT is part of a much bigger wave. ShinyHunters has been on a vishing-to-SaaS rampage that's hit companies across every sector:
- Ameriprise Financial: 48,000 clients, 200GB from Salesforce
- Vercel: supply chain attack through Context.ai
- Kemper Corporation: 13 million records from Salesforce
- 100+ companies: through the same Okta/Entra/Google SSO vishing playbook
The pattern is identical every time. Call an employee. Get the SSO creds. Raid the SaaS apps. Post a ransom demand. Leak if they don't pay.
Every company using Okta, Microsoft Entra, or Google Workspace for SSO is a potential target. The fix isn't complicated: phishing-resistant MFA (like hardware security keys), anomaly detection on SSO logins, and actual security training that teaches employees to hang up the phone. But most companies would rather pay for credit monitoring after the fact than invest in preventing the breach in the first place.
ADT sells home security. They should know better.
Sources
- BleepingComputer: "ADT confirms data breach after ShinyHunters leak threat" (April 24, 2026)
- CyberInsider: "ADT confirms data breach after hacker claims 10 million records stolen" (April 24, 2026)
- Cybersecurity News: "ADT Confirms Data Breach Following ShinyHunters Data Leak Claim" (April 25, 2026)
- Google Cloud: "Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft" (April 2026)
- Malwarebytes: "Security company ADT announces security breach of customer data" (August 2024)
Published: April 27, 2026