---
title: "ADT cloud-environment data incident"
description: "Evidence-backed account of ADT cloud-environment data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/adt-cloud-environment-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/adt-cloud-environment-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/adt-cloud-environment-data-incident-2026/stix.json"
---

# ADT cloud-environment data incident

ADT detected unauthorized access to certain cloud-based environments on April 20, 2026. The incident exposed limited customer and prospective-customer contact and identifying information.

Last modified Aug 9, 2026 · 4 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

[ADT](https://www.adt.com/) detected unauthorized access to certain cloud-based environments on April 20, 2026. [3](#source-3) [4](#source-4)

## Impact

The incident exposed limited customer and prospective-customer contact and identifying information. [1](#source-1) [2](#source-2) [3](#source-3)

Documented data types include:

- Tax identification numbers — Last four digits of Tax IDs in a small percentage of cases. [2](#source-2) [3](#source-3)
- Social Security numbers — Last four digits of Social Security numbers in a small percentage of cases; not full SSNs. [2](#source-2) [3](#source-3)
- Contact information — Phone numbers and physical addresses. [2](#source-2) [3](#source-3)
- Dates of birth — Dates of birth in a small percentage of cases. [2](#source-2) [3](#source-3)
- Contact information — Email addresses represented in the HIBP incident corpus. [2](#source-2) [3](#source-3)
- Names — Names. [2](#source-2) [3](#source-3)

A cited record reports 32,546 individuals (Texas residents in BR-0005212; a non-additive subset; as of 2026-07-28). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 331,536 individuals (Overall notification population in Texas report BR-0005212; regulator-reported and not independently verified; as of 2026-07-28). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 5,488,888 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a person-level notification count; as of 2026-04-27). [1](#source-1) [2](#source-2) [3](#source-3)

## Timeline

### April 20, 2026 — Discovery

Date ADT became aware of and detected the unauthorized access. [4](#source-4)

### April 24, 2026 — Public disclosure

Date of ADT's media statement and SEC Form 8-K. [4](#source-4)

### July 28, 2026 — Public disclosure

Texas Attorney General publication date for report BR-0005212. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

ADT said no payment information, including bank accounts or credit cards, was accessed and customer security systems were not affected or compromised. [3](#source-3)

ADT reported unauthorized access to certain cloud-based environments involving limited customer and prospective-customer data. [4](#source-4)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

ADT said it directly notified all impacted individuals and would offer complimentary identity-protection services as appropriate. ADT said it terminated the unauthorized access, activated its incident-response plan, launched an investigation with third-party cybersecurity experts, and notified law enforcement. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3](#source-3) [4](#source-4)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/adt-cloud-environment-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-2"></a>

### ADT breach record

advisory · Have I Been Pwned · Apr 27, 2026

<https://haveibeenpwned.com/api/v3/breach/ADT>

<a id="source-3"></a>

### ADT detects cybersecurity incident

official · ADT Inc. · Apr 24, 2026

<https://newsroom.adt.com/corporate-news/adt-detects-cybersecurity-incident>

<a id="source-4"></a>

### ADT Inc. Form 8-K — April 20, 2026 cybersecurity incident

regulatory · U.S. Securities and Exchange Commission · Apr 24, 2026

<https://www.sec.gov/Archives/edgar/data/1703056/000170305626000038/adt-20260420.htm>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Organization · 100% confidence · current**  
   ADT customer and prospective-customer data exposure: ADT Inc.
2. **Affected Individual Count · 100% confidence · current**  
   ADT customer and prospective-customer data exposure: 32,546 individual
3. **Resulted In · 100% confidence · current**  
   ADT 2026 incident disclosures and notifications: ADT said it directly notified all impacted individuals and would offer complimentary identity-protection services as appropriate.
4. **Exposed Data Category · 100% confidence · current**  
   ADT customer and prospective-customer data exposure: Tax identification numbers
5. **Affected Individual Count · 100% confidence · current**  
   ADT customer and prospective-customer data exposure: 331,536 individual
6. **Discovered At · 100% confidence · current**  
   April 2026 ADT cloud-environment incident: 2026-04-20
7. **Exposed Data Category · 100% confidence · current**  
   ADT customer and prospective-customer data exposure: Social Security numbers
8. **Resulted In · 100% confidence · current**  
   April 2026 ADT cloud-environment incident: ADT 2026 incident disclosures and notifications
9. **Resulted In · 100% confidence · current**  
   ADT customer and prospective-customer data exposure: ADT said no payment information, including bank accounts or credit cards, was accessed and customer security systems were not affected or compromised.
10. **Exposed Data Category · 100% confidence · current**  
   ADT customer and prospective-customer data exposure: Contact information
11. **Exposed Record Count · 100% confidence · current**  
   ADT customer and prospective-customer data exposure: 5,488,888 record
12. **Affected Organization · 100% confidence · current**  
   April 2026 ADT cloud-environment incident: ADT Inc.
13. **Exposed Data Category · 100% confidence · current**  
   ADT customer and prospective-customer data exposure: Dates of birth
14. **Disclosed At · 100% confidence · current**  
   ADT 2026 incident disclosures and notifications: 2026-04-24
15. **Exposed Data Category · 100% confidence · current**  
   ADT customer and prospective-customer data exposure: Contact information
16. **Exposed Data Category · 100% confidence · current**  
   ADT customer and prospective-customer data exposure: Names
17. **Resulted In · 100% confidence · current**  
   April 2026 ADT cloud-environment incident: ADT reported unauthorized access to certain cloud-based environments involving limited customer and prospective-customer data.
18. **Resulted In · 100% confidence · current**  
   April 2026 ADT cloud-environment incident: ADT said it terminated the unauthorized access, activated its incident-response plan, launched an investigation with third-party cybersecurity experts, and notified law enforcement.
19. **Disclosed At · 100% confidence · current**  
   ADT 2026 incident disclosures and notifications: 2026-07-28
20. **Resulted In · 100% confidence · current**  
   April 2026 ADT cloud-environment incident: ADT customer and prospective-customer data exposure

</details>
