The ShinyHunters ADT data breach of 2026 is one of the clearest examples yet of how extortion gangs operate. In April 2026, the group stole the personal information of 5.5 million people after breaching the systems of ADT, the home security company. The method was not a clever piece of malware. It was a phone call.

What happened at ADT

According to reporting from BleepingComputer, the attackers compromised an ADT employee's Okta single sign-on account through a voice phishing, or "vishing," call. That one compromised account gave them access to ADT's Salesforce instance, where the customer data was stored.

ADT confirmed the breach in late April 2026 after ShinyHunters threatened to leak the stolen data. The company did not say attackers broke through a firewall or exploited a software flaw. They convinced a person to hand over access.

Who is ShinyHunters

ShinyHunters has existed for years, but researchers now describe it as part of a looser, overlapping set of groups sometimes called Scattered Lapsus Hunters, or SLSH. Security firm Mandiant documented a wave of SLSH extortion attacks tracing back to incidents in early to mid-January 2026.

In those incidents, group members posed as internal IT staff and called employees, telling them the company was updating its multi-factor authentication settings. Employees were then directed to fake, victim-branded login pages designed to harvest their single sign-on credentials and MFA codes in real time.

BleepingComputer notes that this vishing approach targets employees and outsourced support staff who hold access to Microsoft Entra, Okta, and Google single sign-on accounts. These centralized logins grant access to many other systems at once.

ADT was not an isolated case

The same month ADT was hit, ShinyHunters claimed to have stolen the personal data of nearly 6 million people from Carnival Cruise. The following month, convenience store chain 7-Eleven confirmed its own breach, with over 183,000 people's data exposed according to Have I Been Pwned.

7-Eleven, founded in 1927, operates more than 86,000 stores worldwide, including 13,000 across the US and Canada. Its loyalty programs serve more than 100 million members. A breach at a company that size shows how much personal data sits behind a single employee login.

The pattern is consistent across all three cases: large organizations, centralized SSO access, and a human being on the other end of the phone doing their job.

Why this matters more than a typical hack

Traditional breach stories often involve a technical vulnerability that gets patched once discovered. Vishing-based breaches are harder to fix with a software update. The weakness is the trust between an employee and a caller claiming to be internal support.

Once attackers gain access to one SSO account, they do not need to keep breaking in. They pivot to whatever SaaS platforms that account can reach. In ADT's case, that was Salesforce, which held the customer records later used for extortion.

These incidents move quickly from quiet theft to public threat. ShinyHunters and similar groups contact the victim company directly, demand payment, and threaten to publish the stolen data if refused.

Where stolen data ends up

Extortion groups use leak sites, including ones hosted as Tor hidden services, to pressure victims and prove they have real data. This is why dark web literacy matters: understanding how these sites work does not require visiting them, and reporting on a breach does not require linking to where stolen data was posted.

If you want to check whether your information has appeared in a breach, use a reputable, independent breach notification service rather than searching for leak sites yourself. Services like Have I Been Pwned exist specifically for this purpose and do not require you to go near the sites where data is traded.

What you can actually do

If you were a customer of ADT, Carnival, or 7-Eleven, or any company caught in this wave, these concrete steps help:

No single tool, including Tor Browser, makes you anonymous by itself. Privacy comes from a combination of habits: what you share, where you log in, and how carefully you verify who is actually asking.

The bigger picture for 2026

The ShinyHunters wave of 2026, from ADT to Carnival to 7-Eleven, shows that extortion groups are hunting for a single distracted employee answering a phone, not for software bugs.

That shift matters for how organizations train staff and for how individuals think about their own exposure. The data these groups steal usually was not yours to protect in the first place. It sat with a company you trusted. Knowing how these breaches happen is the first step toward reacting to them calmly.