ADT cloud-environment data incident

ADT detected unauthorized access to certain cloud-based environments on April 20, 2026. The incident exposed limited customer and prospective-customer contact and identifying information.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

ADT detected unauthorized access to certain cloud-based environments on April 20, 2026. [3][4]

Impact

The incident exposed limited customer and prospective-customer contact and identifying information. [1][2][3]

Documented data types include:

  • Tax identification numbers — Last four digits of Tax IDs in a small percentage of cases. [2][3]
  • Social Security numbers — Last four digits of Social Security numbers in a small percentage of cases; not full SSNs. [2][3]
  • Contact information — Phone numbers and physical addresses. [2][3]
  • Dates of birth — Dates of birth in a small percentage of cases. [2][3]
  • Contact information — Email addresses represented in the HIBP incident corpus. [2][3]
  • Names — Names. [2][3]

A cited record reports 32,546 individuals (Texas residents in BR-0005212; a non-additive subset; as of 2026-07-28). [1][2][3]

A cited record reports 331,536 individuals (Overall notification population in Texas report BR-0005212; regulator-reported and not independently verified; as of 2026-07-28). [1][2][3]

A cited record reports 5,488,888 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a person-level notification count; as of 2026-04-27). [1][2][3]

Timeline

  1. Discovery

    Date ADT became aware of and detected the unauthorized access.

    [4]
  2. Public disclosure

    Date of ADT’s media statement and SEC Form 8-K.

    [4]
  3. Public disclosure

    Texas Attorney General publication date for report BR-0005212.

    [1]
  4. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

ADT said no payment information, including bank accounts or credit cards, was accessed and customer security systems were not affected or compromised. [3]

ADT reported unauthorized access to certain cloud-based environments involving limited customer and prospective-customer data. [4]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

ADT said it directly notified all impacted individuals and would offer complimentary identity-protection services as appropriate. ADT said it terminated the unauthorized access, activated its incident-response plan, launched an investigation with third-party cybersecurity experts, and notified law enforcement. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3][4]