---
title: "Pitney Bowes customer and employee data incident"
description: "Evidence-backed account of Pitney Bowes customer and employee data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/pitney-bowes-customer-employee-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/pitney-bowes-customer-employee-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/pitney-bowes-customer-employee-data-incident-2026/stix.json"
---

# Pitney Bowes customer and employee data incident

A Pitney Bowes supplier data incident corroborated by a downstream government customer and associated with a later-public corpus verified by HIBP. A verified corpus containing unique email addresses and associated identity, contact, and employment information, including downstream Revenue employee account records.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** First-party affected-system boundary; Revenue remains represented as a downstream organization whose employee supplier-account data was exposed.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

A [Pitney Bowes](https://www.pitneybowes.com/) supplier data incident corroborated by a downstream government customer and associated with a later-public corpus verified by HIBP. [1](#source-1)

## Impact

A verified corpus containing unique email addresses and associated identity, contact, and employment information, including downstream Revenue employee account records. [1](#source-1) [2](#source-2)

Documented data types include:

- Names — Names listed by HIBP and reported for the affected Revenue employee subset. [1](#source-1) [2](#source-2)
- Contact information — Email addresses, phone numbers, and physical or office addresses in the corpus and affected Revenue employee subset. [1](#source-1) [2](#source-2)
- Employment information — Job titles in a corpus subset and in the reported Revenue employee fields. [1](#source-1) [2](#source-2)

A cited record reports 8,243,989 records (Unique email addresses represented in HIBP's verified corpus; not a Pitney Bowes-confirmed count of people, customers, employees, accounts, or total database rows; as of 2026-04-27). [1](#source-1) [2](#source-2)

A cited record reports 137 individuals (Revenue employees whose names were confirmed on the affected list; this is a directly bounded downstream subset, not the total number of people represented in the Pitney Bowes corpus). [1](#source-1) [2](#source-2)

Revenue's spokesman said no taxpayer data of any description was involved. [1](#source-1)

After negotiations reportedly failed, some records associated with the incident were published online. [1](#source-1) [2](#source-2)

Revenue security said no passwords were stolen from the affected Revenue employee subset. [1](#source-1)

## Timeline

### April 20, 2026 — Documented event

HIBP BreachDate; not established as the exact initial-access, detection, exfiltration, containment, negotiation, or publication date. [2](#source-2)

### May 19, 2026 — Public disclosure

Publication date of The Irish Times report containing direct Revenue-spokesman confirmation; HIBP had published its corpus record on April 27. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Revenue said every employee on its affected list had been informed and advised about phishing precautions. [1](#source-1)

### Actors

- ShinyHunters

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Revenue's spokesman said the exposed Revenue employee data could contain information supplied when registering for a Pitney Bowes account. Revenue's spokesman said the incident was not a incident of Revenue systems. Revenue's spokesman said the organization had been alerted to the incident and briefed by Ireland's National Cyber Security Centre. The evidence ledger retains 1 disputed claim with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/pitney-bowes-customer-employee-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Revenue staff are warned about passwords after 137 employees caught up in data breach

news · The Irish Times · May 19, 2026

<https://www.irishtimes.com/ireland/2026/05/19/revenue-staff-warned-about-passwords-after-137-employees-caught-up-in-data-breach/>

<a id="source-2"></a>

### Pitney Bowes breach record

advisory · Have I Been Pwned · Apr 27, 2026

<https://haveibeenpwned.com/api/v3/breach/PitneyBowes>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   Pitney Bowes customer and employee contact-data corpus: Revenue's spokesman said no taxpayer data of any description was involved.
2. **Resulted In · 100% confidence · current**  
   April 2026 Pitney Bowes data breach: Revenue said every employee on its affected list had been informed and advised about phishing precautions.
3. **Occurred At · 80% confidence · current**  
   April 2026 Pitney Bowes data breach: 2026-04-20
4. **Affected Organization · 95% confidence · current**  
   April 2026 Pitney Bowes data breach: Pitney Bowes Inc.
5. **Resulted In · 100% confidence · current**  
   Pitney Bowes customer and employee contact-data corpus: Revenue's spokesman said the exposed Revenue employee data could contain information supplied when registering for a Pitney Bowes account.
6. **Resulted In · 95% confidence · current**  
   April 2026 Pitney Bowes data breach: Pitney Bowes customer and employee contact-data corpus
7. **Exposed Data Category · 100% confidence · current**  
   Pitney Bowes customer and employee contact-data corpus: Names
8. **Resulted In · 90% confidence · current**  
   Pitney Bowes customer and employee contact-data corpus: After negotiations reportedly failed, some records associated with the incident were published online.
9. **Attributed To · 70% confidence · disputed**  
   April 2026 Pitney Bowes data breach: ShinyHunters
10. **Affected Organization · 100% confidence · current**  
   April 2026 Pitney Bowes data breach: Office of the Revenue Commissioners
11. **Disclosed At · 100% confidence · current**  
   April 2026 Pitney Bowes data breach: 2026-05-19
12. **Exposed Data Category · 100% confidence · current**  
   Pitney Bowes customer and employee contact-data corpus: Contact information
13. **Exposed Record Count · 100% confidence · current**  
   Pitney Bowes customer and employee contact-data corpus: 8,243,989 record
14. **Affected Individual Count · 100% confidence · current**  
   Pitney Bowes customer and employee contact-data corpus: 137 individual
15. **Resulted In · 100% confidence · current**  
   April 2026 Pitney Bowes data breach: Revenue's spokesman said the incident was not a breach of Revenue systems.
16. **Resulted In · 100% confidence · current**  
   Pitney Bowes customer and employee contact-data corpus: Revenue security said no passwords were stolen from the affected Revenue employee subset.
17. **Exposed Data Category · 100% confidence · current**  
   Pitney Bowes customer and employee contact-data corpus: Employment information
18. **Resulted In · 100% confidence · current**  
   April 2026 Pitney Bowes data breach: Revenue's spokesman said the organization had been alerted to the breach and briefed by Ireland's National Cyber Security Centre.

</details>
