TL;DR
- ADT Inc., one of the largest home and commercial security companies in the U.S., suffered a confirmed data breach on or about April 20, 2026, when a hacker operating under the alias ShinyHunters infiltrated ADT’s network and exfiltrated customer records.
- The hacker claimed to have stolen over 10 million records containing names, phone numbers, addresses, dates of birth, last four digits of Social Security numbers, and Tax IDs; ShinyHunters posted a public extortion demand on a dark-web site threatening to publish the data if ADT did not pay by April 27, 2026.
- ADT publicly stated it “directly notified all impacted individuals,” but the lawsuit alleges ADT issued no actual notification or disclosure to affected individuals, regulatory authorities, or the public explaining the breach’s scope, nature, or potential consequences.
- The complaint alleges ADT deliberately cut corners on cybersecurity spending to boost its own profits, pocketing money customers effectively paid for data protection while storing their most sensitive information on inadequately secured systems.
- The class action, filed May 12, 2026 in the U.S. District Court for the Southern District of Florida (Case No. 9:26-cv-80546), seeks damages, lifetime identity theft monitoring, at least 10 years of credit monitoring, and a court order forcing ADT to actually fix its security infrastructure.
- Victims face lifetime exposure: Social Security numbers cannot be easily replaced, and stolen PII can be weaponized for fraud for years or decades after a breach.
The lawsuit contains a direct accusation that ADT “calculated to increase its own profit” by using “cheap, ineffective security measures” and diverting the savings to itself. That allegation, and what it means for every customer who ever paid ADT for the promise of safety, is documented in full below.
The Non-Financial Ledger
Imagine you hired someone to guard your house. You gave them your address, your date of birth, your Social Security number. You trusted them because that is literally their job. They put a little yard sign out front. And then, while you were sleeping, they left the back door unlocked, someone walked in and took everything, and the guard’s first public response was to say the system “performed as designed.”
That is what Plaintiff (victim of the data breach) Latonia James, a Louisiana resident, and the millions of other people named in this lawsuit are now living with. They did not seek ADT out as an optional luxury. They gave ADT their most sensitive personal data as a condition of getting the company’s services. There was no negotiation. There was no opt-out. Hand over your information or no deal.
Now that information, including partial Social Security numbers, is in the hands of criminals. And here is the part that keeps you up at night: there is nothing you can do to fully fix it. You cannot cancel a Social Security number like a credit card. The Social Security Administration itself warns that replacing a number “will not guarantee you a fresh start” because government agencies and credit bureaus still have records under your old number, and a new number can actually make it harder to get credit because you have no history attached to it.
The FTC estimates that recovering from identity theft takes the average victim 200 hours of work spread over approximately six months. That is five full work weeks. Calling banks. Filing disputes. Proving you are who you say you are. Explaining, over and over, to strangers at call centers, that you did not open that account, take out that loan, or file that tax return. And then doing it again a year later when the stolen data gets sold to a new buyer who tries again.
Studies show that 28% of people affected by a data breach become victims of identity fraud. Before the era of mass breaches, that number was 9.5%. Without any breach, the baseline risk is about 3%. ADT’s customers did not consent to a tenfold increase in their lifetime fraud risk. They paid for security. What they received, the lawsuit alleges, was the opposite.
Beyond the practical nightmare, there is something more corrosive at work. The complaint documents that victims are left “to speculate as to where their PII ended up, who has used it, and for what potentially nefarious purposes.” That uncertainty, that permanent background hum of not knowing, is its own category of harm. Your data is somewhere on a dark-web marketplace right now and no one from ADT has told you where, or precisely what was taken, or what they are doing to make sure it does not happen again. The lawsuit alleges they still have not.
Legal Receipts
The following are verbatim statements from the source documents. They speak for themselves.
“Over 10M records containing PII and other internal corporate data have been compromised. Pay or Leak. This is a final warning to reach out by 27 Apr 2026 before we leak along with several annoying (digital) problems that’ll come your way.”
— ShinyHunters, posted on dark-web extortion site, on or about April 20, 2026 (cited in complaint at ¶6)
- This is the public extortion demand that triggered ADT’s breach disclosure. The scale cited by the attacker is 10 million records. ADT confirmed the breach was real.
- The existence of a payment deadline and a “final warning” establishes that ADT was aware criminals possessed the data at least as of the date this was posted, and customers were not told.
“ADT’s protocols performed as designed: the breach was identified quickly, the threat was contained, and the scope was limited. ADT has directly notified all impacted individuals and will offer complimentary identity protection services as appropriate.”
— ADT Inc. Media Statement, April 24, 2026 (cited in complaint at ¶7 and ¶43)
- The complaint alleges this statement is contradicted by evidence: ADT “has not issued, and does not appear to have issued, any notification or disclosure regarding the Data Breach to affected individuals, regulatory authorities, or the public.” The claim of having “directly notified all impacted individuals” is specifically contested.
- “As appropriate” is doing enormous work in the phrase “offer complimentary identity protection services as appropriate.” The lawsuit documents that ADT has not actually provided meaningful identity theft monitoring to Plaintiff and many class members.
- The statement also provides no information on how the breach occurred, what specific safeguards have been implemented since, or where the stolen data currently exists.
“Defendant enriched itself by hoarding the costs it reasonably should have expended on data security measures to secure Plaintiff’s and Class Members’ Private Information. Instead of providing a reasonable level of security that would have prevented the Data Breach, Defendant calculated to increase its own profit at the expense of Plaintiff and Class Members by utilizing cheap, ineffective security measures and diverting those funds to its own personal use.”
— Class Action Complaint, ¶143, James v. ADT Inc., Case No. 9:26-cv-80546
- This is the central profit-motive allegation. The complaint frames the security failure as a deliberate financial calculation, not an accident or oversight.
- The implication is that ADT’s customers paid a price that was supposed to include the cost of data security, ADT pocketed that portion of the revenue, and customers are now paying the difference with their personal safety.
— Complaint ¶62
Public Deception
ADT’s April 24, 2026 media statement contained multiple claims that the complaint directly contests with documented evidence.
- Claimed: ADT “directly notified all impacted individuals.” Documented reality: The complaint alleges ADT has not issued any notification or disclosure to affected individuals, regulatory authorities, or the public, including any explanation of scope, nature, or potential consequences of the breach.
- Claimed: ADT “will offer complimentary identity protection services as appropriate.” Documented reality: ADT has not provided meaningful identity theft monitoring to Plaintiff and many class members. The services that may have been offered are characterized as “wholly inadequate” because they do not account for the multi-year duration of fraud risk and provide no compensation for the unauthorized disclosure of PII.
- Claimed: “The scope was limited” and “no payment information — including bank accounts or credit cards — was accessed.” Documented reality: The attacker claimed 10 million records were taken. The data compromised includes partial Social Security numbers and Tax IDs, which the complaint establishes are more dangerous in some respects than payment card data because they cannot be canceled and reissued.
- Implied: “Protecting customers is not just a priority — it is the foundation of what ADT does.” Documented reality: The complaint alleges ADT deliberately used “cheap, ineffective security measures” and failed to comply with FTC data security guidelines that the agency has made publicly available to all businesses.
Profit-Maximization at All Costs
The complaint does not frame this as carelessness. It frames it as a financial decision: ADT allegedly chose cheaper security so it could keep more money.
- The complaint alleges that the fees ADT charged customers “included a premium for Defendant’s cybersecurity obligations and were supposed to be used by Defendant, in part, to pay for the administrative and other costs of providing reasonable data security.” ADT collected that money and allegedly did not spend it on what it was implicitly sold for.
- The unjust enrichment count states directly that ADT “enriched itself by hoarding the costs it reasonably should have expended on data security measures” and “calculated to increase its own profit at the expense of Plaintiff and Class Members by utilizing cheap, ineffective security measures and diverting those funds to its own personal use.”
- Customers are described in the complaint as having “overpaid for the services they received without adequate data security.” The gap between what customers paid for and what they received is the financial core of the unjust enrichment claim.
- ADT is characterized as having been “at all times fully aware of its obligations to protect the PII of its customers” and aware “of the significant repercussions that would result from a failure to properly secure the Private Information it maintained.” The alleged profit motive was not ignorant; it was informed.
Societal Impact Mapping
Public Health and Safety
The breach exposed data types that enable harms reaching far beyond financial fraud.
- Social Security numbers and Tax IDs were among the stolen data categories. These identifiers can be used to fraudulently obtain medical goods and services, including prescriptions, enabling medical identity theft that corrupts victims’ health records and can result in dangerous treatment errors for years after the breach.
- The complaint notes that access to Social Security numbers allows criminals to apply for government benefits, mortgages, student loans, and credit cards in victims’ names. These harms can take years to surface and even longer to resolve.
- Victims face documented emotional harm: the complaint specifically identifies “anxiety, emotional distress, loss of privacy, and other economic and non-economic losses” as direct consequences of the breach for Plaintiff and class members.
- The complaint documents that stolen data may be held for “up to a year or more before being used” and that “fraudulent use of that information may continue for years,” meaning class members face an indefinite period of elevated threat, not a finite recovery window.
Economic Inequality
The financial burden of this breach falls hardest on the people least equipped to absorb it.
- The FTC estimates identity theft recovery requires an average of 200 hours of work over approximately six months. That is time that working-class victims cannot bill to a client or reclaim from an employer, and it comes on top of whatever jobs and caregiving responsibilities already fill their hours.
- Victims must personally finance protective measures: credit monitoring subscriptions, credit report fees, credit freeze fees, identity theft protection services, and the cost of time spent on mitigation. ADT offered protection “as appropriate” but the complaint documents that it was not actually provided to Plaintiff and many class members.
- Dark web pricing for stolen identity credentials ranges from $40 to $200 per record for personal information and $50 to $200 for bank details. The 10 million records claimed by ShinyHunters represent a market-valued asset worth potentially hundreds of millions of dollars to criminals, while each individual victim absorbs the cost of the resulting fraud alone.
- The complaint establishes that PII loses value as an asset when exposed. Victims suffer “damages to and diminution of the value of her Private Information, a form of intangible property that loses value when it falls into the hands of criminals.” This is a property loss with no insurance and no reimbursement mechanism for most affected individuals.
- Identity theft statistics establish a clear trend of worsening systemic harm: 6,077 recorded breaches in 2023 alone exposed more than 17 billion records, a 19.8% year-over-year increase. Identity theft complaints nearly doubled over four years, from 2.9 million in 2017 to 5.7 million in 2021. Each major breach like this one adds to that structural accumulation of harm.
Who Pays? Following the Cost
ADT allegedly profited from underinvestment in security; its customers are now being asked to absorb the cost of that decision with their own time, money, and safety.
- From ADT to customers: Customers paid fees that implicitly included a security premium. ADT allegedly retained those funds without delivering the corresponding security. Customers now face out-of-pocket expenses for credit monitoring, credit freezes, identity theft protection, and legal or financial fees to dispute fraudulent accounts.
- From ADT to victims’ time: The FTC’s 200-hour average recovery estimate represents a real-world transfer of labor from victims to the task of cleaning up a mess they did not create. For minimum-wage workers, 200 hours of unpaid protective effort represents thousands of dollars of economic harm that never shows up in a settlement fund.
- From ADT to future victims: The complaint notes that data stolen in this breach “remains unencrypted and available for unauthorized third parties to access and abuse” and is also “backed up in Defendant’s possession” subject to further breaches. The cost of future fraud from this data has not yet been incurred; it is being pre-loaded onto class members’ futures.
- From ADT to public institutions: Government benefits fraud, tax return fraud, and medical fraud enabled by stolen SSNs impose costs on the IRS, the Social Security Administration, Medicaid, and other public programs, meaning taxpayers broadly subsidize the consequences of ADT’s alleged security failures.
The Settlement Isn’t Justice (Yet)
No settlement has been reached as of the filing date. What the complaint is asking for reveals exactly how badly structured any future resolution could be if ADT gets to negotiate its way to a minimum-cost exit.
- ADT’s public offer was identity protection services “as appropriate.” The complaint documents that this phrase is meaningless in practice because no meaningful services were actually delivered to Plaintiff and many class members. The word “appropriate” gave ADT permission to define its own obligation down to nearly nothing.
- The complaint demands “not less than ten years of credit monitoring services” for all class members as a baseline. The FTC’s own research supports that stolen data can be exploited for years after a breach, making anything less than a decade of monitoring structurally inadequate for a breach of this type.
- The complaint requests lifetime identity theft protective services for Plaintiff and class members, recognizing that Social Security numbers, once exposed, create permanent vulnerability. A one-time or two-year credit monitoring subscription, which is the industry-standard corporate settlement offer, addresses a lifetime harm for about 24 months.
- The unjust enrichment count specifically demands “full refunds, restitution, and/or damages from Defendant and/or an order proportionally disgorging all profits, benefits, and other compensation obtained by Defendant from its wrongful conduct.” This is a demand for ADT to give back the money it allegedly saved by not investing in adequate security. Without disgorgement, the financial incentive structure that produced this breach remains intact.
- The complaint also requests future annual audits of ADT’s data security systems as part of any injunctive relief. Without ongoing court-supervised auditing, a consent decree or settlement with no enforcement mechanism simply resets the clock on the next breach.
The Human Cost in Numbers
The average time the FTC estimates a single identity theft victim must spend over approximately six months to recover. Multiply that by the 10 million records claimed stolen. That is potentially 2 billion hours of unpaid human labor generated by a single corporate security failure, if every exposed record is weaponized.
The share of data breach victims who become victims of identity fraud, per the cited study. The baseline rate without any breach is 3%. ADT’s alleged security failure multiplied each customer’s fraud risk by more than nine times. For comparison, a 2012 study found only 9.5% of breach victims faced fraud, meaning the threat has nearly tripled in severity over that period.
Explore by category
Product Safety Violations
When companies sell dangerous goods, consumers pay the price.
View Cases →Financial Fraud & Corruption
Lies, scams, and executive impunity that distort markets.
View Cases →


