June 17, 2026: Eastman Kodak confirmed to BleepingComputer that hackers accessed company data—while the ShinyHunters extortion group simultaneously claimed it stole more than 2.2 million customer and corporate records. Kodak's own words: a limited amount of data. The group's marketing: millions. Same incident, two very different numerators.
What Kodak confirmed
Kodak told reporters an unauthorized third party gained temporary access to a limited amount of company data. The Rochester imaging company said it promptly brought in external cybersecurity experts, is working with law enforcement, and believes there is no ongoing threat to systems or operations.
That is the full official picture so far. Kodak has not named ShinyHunters as the culprit, has not published a victim count, and has not listed which data fields were copied.
What ShinyHunters says
ShinyHunters added Kodak to its Tor leak site ahead of the company statement, alleging 2.2 million-plus records of customer personally identifiable information and internal corporate files. The group set a June 18, 2026 deadline for Kodak to contact them before public release—standard pay-or-leak choreography.
Trade press including Malwarebytes noted the group had not published proof samples at initial reporting. That pattern—big number, short deadline, no verified dump—is common in 2026 extortion campaigns where actors pressure negotiations before forensics finishes.
Two numbers, one breach
Kodak's "limited amount" and ShinyHunters' "2.2 million" are not necessarily contradictory in the way headlines make them sound. Forensic teams count what they can prove was accessed for notification law. Extortion groups count whatever rows they think they can sell on a forum. Until Kodak or a regulator publishes letters, treat the 2.2M figure as unverified actor marketing and the confirmed fact as: data left the building in some quantity.
Context matters too: Kodak today is a commercial print and advanced-materials vendor more than a mass consumer-photo brand. A breach still hurts B2B customers, partner portals, and anyone with a lingering Kodak.com account—but the blast radius depends on what was actually in the exfiltration set, which Kodak has not itemized.
ShinyHunters in mid-2026
Kodak landed on the leak site during the same summer wave that hit Salesforce tenants, Oracle PeopleSoft zero-days, and healthcare archives like One Medical Seniors. The group's playbook in 2026 is less about encrypting servers and more about stealing SaaS and file-store exports, then threatening publication. BleepingComputer linked Kodak to that broader campaign narrative without Kodak confirming the intrusion path.
What to do if you use Kodak services
- Change your Kodak password if you have an account—and anywhere you reused it.
- Turn on MFA on Kodak-linked email; a stolen password should not be enough to take over the account.
- Ignore leak-site downloads. Criminal archives often carry malware and re-victimize people whose data is already exposed.
- Wait for an official notice before assuming your row is in the 2.2M set. State breach laws and GDPR will force letters once scope is known.
- Watch for phishing citing real order IDs or partner names if partial samples circulate.
Canonical record
Eastman Kodak 2026 on BreachHistory.
Sources: BleepingComputer, SecurityWeek, Malwarebytes.