← ADT Inc

2026 ADT — vishing → Okta/Salesforce path; ~5.5M in state filings vs “limited set” language; ShinyHunters leak (Apr)

2026 5.5M records affected Share on X

Data compromised

Customer and prospect PII including contact, address, DOB, partial SSN/tax ID in regulatory summaries—categories vary by person

Technical writeup

Media coverage contextualized this April 2026 incident as roughly the third major ADT-linked cybersecurity publicity cycle in approximately two years, following earlier disclosures that consumer reporting frequently referenced for pattern analysis. U.S. home-security provider ADT publicly confirmed a cyber intrusion discovered around April 20, 2026, tied in many outlets to vishing or social-engineering pressure against employee Okta single sign-on that enabled access to Salesforce-oriented customer and operations data, followed by ShinyHunters exfiltration and pay-or-leak marketing; BleepingComputer and follow-on summaries cited state regulatory aggregates on the order of ~5.5 million affected individuals (names, emails, phones, addresses, DOB, partial tax/ID fields per filings) while the company’s own statements sometimes emphasized a narrower “limited set” versus actor claims of ~10M rows. Payment cards and in-home security equipment were routinely described as outside theft scope in corporate messaging.

Root cause

Vishing/social engineering against workforce SSO enabling Salesforce data access; criminal exfiltration (per press and regulator-facing summaries)

References