Pitney Bowes customer and employee data incident

A Pitney Bowes supplier data incident corroborated by a downstream government customer and associated with a later-public corpus verified by HIBP. A verified corpus containing unique email addresses and associated identity, contact, and employment information, including downstream Revenue employee account records.

Last modified

Summary

  • Environment: First-party affected-system boundary; Revenue remains represented as a downstream organization whose employee supplier-account data was exposed.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

A Pitney Bowes supplier data incident corroborated by a downstream government customer and associated with a later-public corpus verified by HIBP. [1]

Impact

A verified corpus containing unique email addresses and associated identity, contact, and employment information, including downstream Revenue employee account records. [1][2]

Documented data types include:

  • Names — Names listed by HIBP and reported for the affected Revenue employee subset. [1][2]
  • Contact information — Email addresses, phone numbers, and physical or office addresses in the corpus and affected Revenue employee subset. [1][2]
  • Employment information — Job titles in a corpus subset and in the reported Revenue employee fields. [1][2]

A cited record reports 8,243,989 records (Unique email addresses represented in HIBP’s verified corpus; not a Pitney Bowes-confirmed count of people, customers, employees, accounts, or total database rows; as of 2026-04-27). [1][2]

A cited record reports 137 individuals (Revenue employees whose names were confirmed on the affected list; this is a directly bounded downstream subset, not the total number of people represented in the Pitney Bowes corpus). [1][2]

Revenue’s spokesman said no taxpayer data of any description was involved. [1]

After negotiations reportedly failed, some records associated with the incident were published online. [1][2]

Revenue security said no passwords were stolen from the affected Revenue employee subset. [1]

Timeline

  1. Documented event

    HIBP BreachDate; not established as the exact initial-access, detection, exfiltration, containment, negotiation, or publication date.

    [2]
  2. Public disclosure

    Publication date of The Irish Times report containing direct Revenue-spokesman confirmation; HIBP had published its corpus record on April 27.

    [1]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Revenue said every employee on its affected list had been informed and advised about phishing precautions. [1]

Actors

  • ShinyHunters

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Revenue’s spokesman said the exposed Revenue employee data could contain information supplied when registering for a Pitney Bowes account. Revenue’s spokesman said the incident was not a incident of Revenue systems. Revenue’s spokesman said the organization had been alerted to the incident and briefed by Ireland’s National Cyber Security Centre. The evidence ledger retains 1 disputed claim with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]