← Blog

Fluke Breach: 821K Emails in ShinyHunters Dump

Share on X

July 15, 2026: Have I Been Pwned added Fluke Corporation after indexing published data from a ShinyHunters pay-or-leak campaign. The load covers 821,100 unique email addresses—mostly corporate contacts tied to the Fortive-owned test-and-measurement giant.

What landed on HIBP

Troy Hunt's service says the corpus includes emails plus names, phone numbers, physical addresses, employers, job titles, and a large set of support tickets. That is enough to spoof vendor invoices and "meter calibration" follow-ups without needing payment-card data.

ShinyHunters listed Fluke on its leak site on July 2, 2026, claiming more than 100GB and over 21 million Salesforce records. HIBP's email count is lower and more conservative—we index the 821K attested figure, not the actor's Salesforce marketing number.

Separate from Fluke's 2025 California notice

Fluke already appears on California's AG breach list for an intrusion window spanning August 10 to October 7, 2025, with trade press citing roughly 18,000 people notified over SSNs and related fields. The July 2026 ShinyHunters dump is a different published dataset with a different scale and timeline. Treat them as two rows, not one updated count.

Who should care

Industrial electricians, biomedical technicians, and OEM partners who buy Fluke meters, scopes, or process calibrators often reuse work emails on support portals. Those addresses are now in a public dump alongside ticket history—perfect raw material for targeted phishing.

Action items

  1. Check haveibeenpwned.com for any email used with Fluke accounts.
  2. Verify purchase-order and RMA requests through known account managers—not reply links.
  3. Enable MFA on vendor portals that still accept password-only login.
  4. Ignore "data leak download" posts; rotating credentials beats collecting stolen dumps.

Canonical record: Fluke Corporation 2026 on BreachHistory. Sources: HIBP, BreachNews.