ShinyHunters Vishing Breach Hits ADT, 5.5M Records Exposed
Voice‑phishing attack on an Okta SSO account gave ShinyHunters access to 5.5 million ADT customer emails, names, phones and partial SSNs. No payment data was taken.

TL;DR
ShinyHunters used voice phishing to steal an employee’s Okta SSO credentials and accessed ADT’s customer database, exposing 5.5 million email addresses and personal details. Payment card data was not taken, but names, phones, addresses and partial SSNs were compromised.
Context
ADT provides security systems to millions of homes and businesses. On April 20 its internal monitoring flagged unauthorized access to a limited set of customer and prospect data. The company immediately terminated the intrusion, launched a forensic investigation with third‑party experts and notified law enforcement.
Key Facts
- The breach exposed 5.5 million unique email addresses belonging to ADT customers. - Exposed fields included names, phone numbers, mailing addresses and, for a subset, Social Security or Tax ID numbers. - Payment card information was not compromised according to ADT’s statement. - ShinyHunters gained entry by compromising an employee’s Okta single‑sign‑on credential via a voice‑phishing (vishing) call. - The attackers then navigated the Okta SSO portal to reach the ADT Salesforce environment where customer records were stored. - This technique maps to MITRE ATT&CK T1566.002 (Voice Phishing).
What It Means
The incident shows that even strong SSO platforms can be bypassed when attackers defeat the human factor with vishing. Organizations should enforce phishing‑resistant MFA, monitor Okta login anomalies, and restrict SSO access to least‑privilege roles. Defenders should also train staff to recognize unsolicited calls requesting credentials and implement call‑verification procedures. Watching for follow‑on activity, such as the appearance of the stolen data on underground markets or attempts to use the partial SSNs for identity fraud, will be critical in the coming weeks.
Continue reading
More in this thread
Medtronic Confirms Corporate IT Data Breach, Says No Impact on Patient Safety or Finances
Peter Olaleru
ShinyHunters Voice-Phishing Attack Exposes 5.5 Million ADT Customer Emails
Peter Olaleru
New York Sports Fans Face High Password Breach Risk, Yankees and Rangers Top List
Peter Olaleru
Conversation
Reader notes
Loading comments...