ADT, one of the largest home security companies in the United States, confirmed in April 2026 that its computer systems were breached by cybercriminals who accessed a portion of its customer and prospective-customer data. The intrusion has since been linked to the ShinyHunters hacking group, which claimed responsibility and threatened to publish the stolen records unless a ransom was paid.
Companies that store personal information about millions of customers have a responsibility to protect that data with reasonable security measures, and to notify affected individuals promptly when a breach occurs.
ADT’s Data Breach Investigation
ADT is a Florida-based provider of home and business security systems, offering monitored alarm, video surveillance, and smart-home services to millions of customers across the country. In late April 2026, the company detected unauthorized activity within its computer network and launched an internal investigation with the help of third-party cybersecurity specialists.
According to ADT’s own public statement, the investigation determined that an unauthorized party had accessed a limited set of customer and prospective customer data. However, the security community soon identified the incident as part of a larger extortion campaign. The hacking group ShinyHunters listed ADT on its dark-web leak site as part of a pay-or-leak scheme, setting a deadline for the company to pay a ransom or have the stolen data published. The group publicly claimed to have obtained more than 10 million records, including personally identifiable information and internal corporate data, a figure significantly larger than what ADT initially disclosed.
The incident was later added to the breach-notification database Have I Been Pwned, which lists approximately 5.5 million affected accounts nationwide. As part of its state-by-state legal notification obligations, ADT also filed notice with the Florida Attorney General’s Office, reporting that 32,546 Florida residents were affected by the breach.
Breaches involving companies like ADT are especially concerning because of the nature of the service they provide. Customers give a home security company not only their contact information but also details tied to the physical security of their homes and families, creating an added layer of vulnerability when that information falls into the wrong hands. The technology and security services sector has increasingly become a target for large-scale extortion groups like ShinyHunters, which have claimed responsibility for a string of high-profile breaches in 2026 alone, including incidents affecting the European Commission’s cloud infrastructure, the gaming company Rockstar Games, and the customer-relationship platform Salesforce.
Exposure of names, phone numbers, physical addresses, and in some cases partial Social Security or Tax ID numbers and dates of birth creates a real risk of follow-up harm. Even when full Social Security numbers are not exposed, cybercriminals frequently combine partial identifiers with other leaked or purchased data to build a complete profile of a victim, which can then be used for identity theft, targeted phishing campaigns, or fraudulent account openings. Consumers whose data was exposed in a breach of this kind are often targeted with follow-up phishing emails or phone calls that impersonate the breached company, attempting to extract additional sensitive information under the guise of verifying an account after a breach.
ADT has stated that no payment information, including bank account or credit card numbers, was accessed in the breach, and that its physical security monitoring systems were not affected. The company says it has notified all individuals it has identified as impacted and is offering complimentary identity protection services where appropriate. Law enforcement has also been notified of the incident.
This is not the first time ADT has been the target of a cyberattack; the company also disclosed a separate cybersecurity incident in 2024. Repeated incidents at the same organization can raise additional questions about whether adequate safeguards were put in place after an earlier breach to prevent a similar event from happening again.
When Did This Breach Occur?
ADT detected unauthorized activity on its network on April 20, 2026, and confirmed shortly afterward that hackers had accessed customer data. Have I Been Pwned lists the breach as occurring in April 2026, with the incident added to its database on April 27, 2026, once ADT’s public statement and the ShinyHunters group’s own leak-site claims made the scope of the intrusion clear.
Notification to affected individuals and to state regulators followed in the months after the breach was discovered. ADT’s notice to the Florida Attorney General’s Office, reporting that 32,546 Florida residents were impacted, was published on July 28, 2026. Multi-state breaches like this one are often reported to different states’ offices on different timelines, depending on each state’s own notification laws.
What Information Was Breached?
ADT has confirmed that the information accessed in the breach included customers’ and prospective customers’ names, phone numbers, and physical addresses. The company also disclosed that, in a smaller percentage of cases, the exposed data included dates of birth and the last four digits of Social Security numbers or Tax ID numbers.
ADT has stated that no payment card numbers or bank account information were compromised, and that customers’ physical security systems and monitoring services were not affected by the breach.
What You Can Do
If you received a notice that your information was involved in the ADT data breach, or if you were a current or prospective ADT customer during this period, there are steps you can take to help protect yourself:
- Review any notification letter you receive from ADT carefully and keep a copy for your records.
- Enroll in any complimentary identity protection or credit monitoring services ADT offers to affected customers.
- Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion).
- Monitor your bank and credit card statements, as well as your credit reports, for unfamiliar activity.
- Be cautious of unsolicited calls, texts, or emails claiming to be from ADT that ask you to verify your account or personal information.
File a Data Breach Lawsuit Against ADT
Companies that collect sensitive personal information from millions of customers, including a home security company entrusted with the safety of its customers’ homes and families, have a legal responsibility to implement reasonable safeguards to protect that data. When a breach like this occurs, affected individuals may be entitled to pursue compensation for the harm caused by the exposure of their personal information.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.