June 26, 2026: Telecommunications tower giant American Tower appeared in ShinyHunters' Oracle PeopleSoft zero-day extortion wave. After a pay-or-leak deadline, published data was indexed on Have I Been Pwned as 217,000+ unique email addresses—American Tower had not publicly confirmed at HIBP load time.
What HIBP indexed
Compromised data categories include email addresses, names, job titles, phone numbers, and physical addresses spanning employees, contractors, customers, and leads—including landowners and municipal partners in the tower ecosystem.
PeopleSoft campaign context
American Tower was one of multiple ShinyHunters victims in the June 2026 Oracle PeopleSoft zero-day campaign also affecting the NAIC and other enterprises. See the broader pattern in BleepingComputer's reporting.
What to do
- Check HIBP for your email address.
- Enable MFA on work and vendor portals tied to American Tower.
- Watch for phishing citing real tower-site addresses or lease details.
Canonical record: American Tower ShinyHunters 2026 on BreachHistory.