← Blog

Inter-Con Security Breach: 276K Emails on HIBP

Share on X

August 5, 2026 (HIBP) / June 2026 incident: Inter-Con Security Systems, Inc.—the Pasadena, California private security company behind icsecurity.com—moved from an unverified ShinyHunters extortion listing to a Have I Been Pwned–attested dump. HIBP loaded 276.1k unique email addresses with names, physical addresses, job titles, employers, and phone numbers spanning contacts, internal users, and leads.

BreachHistory’s canonical row is ic-security-shinyhunters2026. Earlier June coverage (and our first catalog note) treated the victim as a generic “cybersecurity firm” and indexed ShinyHunters’ ~2.7 million records marketing claim as unverified. That actor figure is not the HIBP unique-email count. Treat 276,100 as the verified denominator until a regulator publishes a different attested census.

What happened

In early June 2026, Inter-Con was pulled into ShinyHunters’ pay-or-leak wave. ClaimDepot and related consumer notices place an intrusion around June 5, 2026; ShinyHunters publicized the company around June 18. Indiana Attorney General breach reporting was cited around June 23. Plaintiff firms later advertised investigations referencing the same ~2.7 million figure that appeared in actor marketing.

What changed on August 5, 2026 is attestation quality: Have I Been Pwned’s Inter-Con Security card documents a published corpus with a concrete unique-email count and field list. That is the same verification model BreachHistory uses for Houston City College, Glendale Community College, and other mid-2026 ShinyHunters dumps once Troy Hunt’s project loads the files.

Inter-Con provides guard and risk-management services to government and commercial clients. Confusing the brand with a boutique MSSP is easy when leak-site titles shorten the name to “IC Security”—but the dump HIBP processed is contact- and workforce-shaped PII, not a SOC tooling vault.

What data was exposed

According to HIBP, compromised data types include:

  • Email addresses (276.1k unique)
  • Names
  • Physical addresses
  • Phone numbers
  • Job titles
  • Employers

HIBP describes the mix as contacts, internal users, and leads. That combination supports convincing B2B and employment phishing: fake badge renewals, “updated post orders,” contractor onboarding portals, and payroll redirects that cite a real job title and work address.

What the 2.7 million figure means

Law-firm alerts and some aggregators still headline approximately 2.7 million records. Actor row counts often inflate beyond unique individuals—duplicate CRM rows, historical leads, multi-system joins, or marketing hyperbole. BreachHistory keeps that figure in the write-up as actor/litigation context and catalogs 276,100 from HIBP as the verified email denominator. If Inter-Con or a state AG later publishes a higher notified-person total that is independently attested, the catalog should be revised.

Who is at risk

Current and former Inter-Con employees and contractors whose work emails or personal emails appear in the dump; commercial and government client contacts and leads stored in Inter-Con systems; and anyone who reused an Inter-Con-related password elsewhere. Private security firms sit on schedules, site lists, and VIP contact graphs—secondary social engineering after a dump can target client sites, not just Inter-Con’s own inbox.

How this fits the 2026 ShinyHunters wave

June 2026 was dense with ShinyHunters brand hits across education, retail, and enterprise CRM. Inter-Con is notable because the victim is a physical-security provider: attackers get both workforce PII and a rolodex of facilities that hire guards. Compare Brinks Home and other security-adjacent disclosures from the same campaign season—different products, same extortion playbook of steal, threaten, publish, then watch HIBP and class-action firms finish the publicity cycle.

Practical phishing patterns to expect

After security-vendor and security-services dumps, attackers rarely lead with “we stole your data.” They lead with operational urgency: a badge that “expired,” a client site that “needs overnight coverage,” a W-9 that “must be re-signed,” or a Microsoft 365 “session refresh” that looks like Inter-Con IT. Job title plus employer plus phone number is enough to pass the first human sniff test on a help desk.

If you are a client contact, treat unexpected requests to change wiring instructions, emergency call trees, or visitor lists as high risk for the next several months. Confirm out-of-band using a phone number you already had—not a number in the suspicious email signature.

Catalog note for researchers

BreachHistory originally indexed this incident under the shortened brand “IC Security” while the claim was still unverified actor marketing. The company slug /ic-security/ remains for URL stability. The display name and classification now correctly identify Inter-Con Security Systems as a private security provider. Researchers comparing June leak-site screenshots to the August HIBP card should expect the 2.7M vs 276.1k discrepancy and not treat them as the same metric.

Action items

  1. Check Have I Been Pwned for every email you used with Inter-Con or as a client contact.
  2. Watch badge, payroll, and “site access” phishing that name-drops Inter-Con, a real job title, or a known facility.
  3. Change reused passwords on email, banking, and employer SSO if you recycled an Inter-Con-related credential.
  4. Enable MFA on personal email and any remaining Inter-Con or client portals.
  5. Clients: review whether Inter-Con held schedules, emergency contacts, or VIP lists for your sites and brief security desks accordingly.
  6. Freeze credit only if a later AG or company notice expands exposure to SSN or government ID—HIBP’s current field list does not attest those.

Canonical record

Inter-Con Security 2026 on BreachHistory — HIBP-verified 276,100 emails; ShinyHunters campaign context; prior unverified 2.7M claim superseded as the catalog denominator.

Sources: Have I Been Pwned, ClaimDepot summary, PR Newswire investigation notice, DeXpose (initial claim coverage).

Updated 2026-08-06.