Summary
- Environment: First-party affected-system boundary; Revenue remains represented as a downstream organization whose employee supplier-account data was exposed.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
A Pitney Bowes supplier data incident corroborated by a downstream government customer and associated with a later-public corpus verified by HIBP. [1]
Impact
A verified corpus containing unique email addresses and associated identity, contact, and employment information, including downstream Revenue employee account records. [1][2]
Documented data types include:
- Names — Names listed by HIBP and reported for the affected Revenue employee subset. [1][2]
- Contact information — Email addresses, phone numbers, and physical or office addresses in the corpus and affected Revenue employee subset. [1][2]
- Employment information — Job titles in a corpus subset and in the reported Revenue employee fields. [1][2]
A cited record reports 8,243,989 records (Unique email addresses represented in HIBP’s verified corpus; not a Pitney Bowes-confirmed count of people, customers, employees, accounts, or total database rows; as of 2026-04-27). [1][2]
A cited record reports 137 individuals (Revenue employees whose names were confirmed on the affected list; this is a directly bounded downstream subset, not the total number of people represented in the Pitney Bowes corpus). [1][2]
Revenue’s spokesman said no taxpayer data of any description was involved. [1]
After negotiations reportedly failed, some records associated with the incident were published online. [1][2]
Revenue security said no passwords were stolen from the affected Revenue employee subset. [1]
Timeline
Documented event
HIBP BreachDate; not established as the exact initial-access, detection, exfiltration, containment, negotiation, or publication date.
[2]Public disclosure
Publication date of The Irish Times report containing direct Revenue-spokesman confirmation; HIBP had published its corpus record on April 27.
[1]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Revenue said every employee on its affected list had been informed and advised about phishing precautions. [1]
Actors
- ShinyHunters
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
Revenue’s spokesman said the exposed Revenue employee data could contain information supplied when registering for a Pitney Bowes account. Revenue’s spokesman said the incident was not a incident of Revenue systems. Revenue’s spokesman said the organization had been alerted to the incident and briefed by Ireland’s National Cyber Security Centre. The evidence ledger retains 1 disputed claim with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]
