Data Breaches
Why the Same Hacking Crew Just Breached Two Security Companies You Trust
Bottom line: In 2026, two companies millions of people trust to keep them safe — home security giant ADT and identity-protection company Aura — were both broken into by the same hacking group, using the same trick both times. The attackers didn't crack any passwords or break any encryption. They picked up the phone, called an employee at each company, and talked their way into the network. This matters to you even if you've never heard of either company by name, because it shows the single biggest threat to your accounts right now isn't a hacker guessing your password — it's a hacker talking a company's own staff into handing over the keys.
Last updated: 2026-07-28
What Actually Happened
A hacking crew tracked by security researchers under the name ShinyHunters broke into internal systems at both ADT and Aura within the same general window in 2026. These are two very different companies — ADT sells home alarm systems and monitoring; Aura sells identity theft protection and credit monitoring — but the break-in method was identical at both.
Here's the pattern:
- The attackers researched the company and identified an employee, often in IT support or a help desk role, who had the authority to reset passwords or grant account access.
- They called that employee — or a colleague who could reach them — posing as a fellow employee locked out of their account, or as IT support itself.
- Using confidence, urgency, and details that sounded legitimate, they convinced the employee to reset a password, approve a login, or bypass a security step.
- Once inside, they moved through internal systems and accessed customer data.
This technique has a name: vishing, short for "voice phishing." Instead of a fake email with a bad link, it's a phone call designed to manipulate a real person into making a mistake. No malware, no hacking tools, no exploited software bug — just a convincing conversation.
The reason this is worth paying attention to is that it worked twice, against two companies whose entire business is protecting people from exactly this kind of attack. If a security company's own staff can be talked into opening the door, the same trick can work on any company holding your data — your bank, your utility provider, your doctor's office.
Why This Is Different From a Typical Data Breach
Most data breach news follows a familiar script: a company's database gets hacked, and afterward you're told to change your password. This one is different in an important way.
When a database is stolen, the fix is usually clear — change the password on that one account, maybe turn on two-factor authentication, and move on. But when attackers get in by fooling an employee into granting access, they may be able to reach far more than a single database. Depending on what that employee could see or do, the attackers could potentially view account details, service records, contact information, and in some cases enough personal information to attempt further scams — including calling you directly, pretending to be the very company you trusted.
That last part is the twist seniors especially need to understand: a breach like this can become the setup for a second scam. If attackers pulled customer names, phone numbers, and account details from ADT or Aura, that same information can be used to make a follow-up scam call sound completely convincing — "Hi, this is ADT security, we're verifying your account after a recent incident..." The breach itself is bad. The phone call that might come after it can be worse.
Who Is ShinyHunters, and Why Do They Keep Winning This Way?
ShinyHunters isn't a new name in the security world — the group has been linked to breaches at a long list of well-known companies over the past several years, typically by stealing large batches of customer data and then selling it or leaking it. What makes the ADT and Aura incidents notable isn't that ShinyHunters breached two companies — it's that they used the exact same social engineering playbook against two organizations whose entire job is to stop this kind of thing.
That's not a coincidence, and it's not bad luck. It reflects a hard truth about cybersecurity: technical defenses have gotten very good. Firewalls, encryption, intrusion detection — modern companies invest heavily in all of it, and it works. What hasn't kept pace is training ordinary employees to recognize a manipulative phone call. A help desk worker's job is to be helpful and move quickly. An attacker who sounds confident, uses real internal terminology, and creates a sense of urgency can exploit that helpfulness in under two minutes.
Security researchers who track this group note that the calls are rarely rushed or clumsy. The attackers often do homework beforehand — checking employee directories on LinkedIn, company org charts, even social media posts — so the call sounds like it's coming from someone who belongs. That's why "just train employees to spot scams" is easier said than done. The good calls don't feel like scams while they're happening.
If You're an ADT or Aura Customer, Do This Now
You don't need to panic, but you do need to take a few concrete steps.
1. Change your account password — even if you weren't told to.
Companies don't always notify every affected customer immediately, and notifications can take weeks. Log in directly through the official app or website (never through a link in an email or text) and set a new, unique password.
2. Turn on two-factor authentication if it isn't on already.
This means a code gets sent to your phone or a separate app any time someone tries to log in. Even if a hacker has your password, this stops them cold. Both ADT and Aura offer this option in account settings.
3. Be suspicious of any phone call claiming to be from ADT or Aura.
This is the most important step. If someone calls claiming to be from either company — saying there's been "suspicious activity," asking you to "verify your account," or asking for a code that was just texted to you — hang up. Call the company back using the number on your original account paperwork or their official website, not a number the caller gives you. Legitimate security and monitoring companies will never ask you to read back a one-time verification code over the phone. If you want a deeper look at how these follow-up calls are scripted, our guide on tech support scam calls breaks down the same pressure tactics in detail.
4. Watch your bank and credit card statements for the next several months.
Set a reminder to check statements weekly rather than relying on memory. Stolen account information sometimes isn't used for months, as scammers wait for people to stop watching closely. Setting up bank fraud alerts ahead of time means you get notified automatically instead of relying on catching something during a manual check.
5. Consider a service that watches for you automatically.
Checking manually is good, but it's easy to let it slide after a few weeks. This is where a monitoring service earns its cost — it watches continuously and alerts you the moment something changes, so you don't have to remember to check.
If You're Not an ADT or Aura Customer, This Still Applies to You
The reason this story matters beyond the two companies named is the method, not the target. Vishing attacks are rising sharply because they bypass almost every technical security measure a company puts in place — firewalls, encryption, fraud detection software — none of that stops a human being from making a bad decision on a phone call.
That means the same approach can be used against any company that holds your information, including ones you deal with directly:
- A caller claiming to be from your bank's fraud department, asking you to "confirm" your card number.
- A caller claiming to be Medicare, Social Security, or your pharmacy, asking to "verify" your identity.
- A caller claiming to be tech support for a device you own, asking for remote access to your computer.
The single best defense is the same in every case: you hang up and call back using a number you already know is real — printed on your card, your statement, or the company's official website. Nobody legitimate will object to that.
Three Phrases That Should Make You Hang Up Immediately
Scammers who use this vishing method tend to rely on a small handful of pressure phrases, because they work. Learn to recognize them:
- "We've detected suspicious activity on your account and need to verify your identity right now." Real companies don't need you to act "right now" over the phone. They can send a letter, an app notification, or wait for you to call back.
- "Can you read me the code we just texted you?" This is almost always an attempt to steal a two-factor authentication code in real time. No legitimate company representative will ever ask for this. The code exists specifically so you can prove it's you logging in — not so you can hand it to someone else.
- "I'm from the fraud department, and if we don't fix this today, your account will be locked." Urgency plus a threat is the oldest trick in the book. A real fraud department can put a temporary hold on an account without demanding immediate action from you over the phone.
If you hear any of these, the safest response is the same every time: say you'll call back, hang up, and dial the number printed on your bill, card, or the company's official app — never a number the caller provides.
What Companies Like ADT and Aura Should Be Doing Differently
It's worth being clear that the responsibility here doesn't fall on customers alone. Companies that hold sensitive personal data have a duty to make these kinds of social engineering attacks harder to pull off, and incidents like this typically push the entire industry toward stronger internal controls, including:
- Requiring multiple layers of verification before any employee can reset a customer account or grant elevated access, so no single phone call is enough.
- Limiting how much customer data any one employee can view at once, so a single compromised login doesn't expose the entire customer base.
- Running regular, unannounced tests where security teams attempt to vish their own employees, to find weak spots before real attackers do.
If you're a customer of either company, it's reasonable to expect a public statement addressing exactly these kinds of safeguards. If one hasn't been published yet, that's worth watching for.
Choosing an Identity Protection Service After News Like This
It might feel strange to recommend identity protection right after describing a breach at an identity protection company. But the lesson here isn't "don't trust any of these services" — it's "understand what they actually protect against, and choose one that's transparent when something goes wrong."
A breach caused by an employee being tricked on a phone call is a company security failure, not a flaw in the concept of monitoring your identity. The value of a good identity protection service is what happens after your information is exposed anywhere — not just at one company, but anywhere on the internet, including the dark web marketplaces where stolen data eventually ends up for sale. If you're weighing whether Aura is still the right pick after this news, our Aura vs. McAfee comparison breaks down how the two all-in-one protection services actually differ.
Try Aura — Plans Start at $12/Month
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
If home security is your main concern rather than identity monitoring, it's also worth knowing that ADT isn't the only option, and for many households it isn't even the best value. Our comparison of ADT alternatives and our side-by-side look at Ring vs. SimpliSafe both cover systems that offer comparable monitoring without a long contract.
See SimpliSafe Plans and Pricing
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
Whichever service you use, the two things that matter most are two-factor authentication on your own account, and a healthy suspicion of any phone call that asks you to "verify" something urgently.
The One Habit That Would Have Stopped This
If there's a single takeaway from the ADT and Aura incidents, it's this: the attackers didn't need to be clever with computers. They needed one employee, on one phone call, to skip a verification step because the caller sounded confident and the situation sounded urgent.
That's exactly the same pressure scammers use on individuals — a rushed, official-sounding phone call designed to make you act before you think. The fix is identical whether you're a help desk employee or a retiree at home: slow down, hang up, and call back on a number you already trust. It's the simplest habit in cybersecurity, and it's the one that actually stops this kind of attack.
Stay Ahead of the Next Breach
New breaches get reported every week, and it's easy to miss the ones that affect you. Sign up below and we'll send you a plain-English alert whenever a company you likely use gets breached — along with the exact steps to take, no jargon required.
Stay Updated
Join our newsletter for the latest updates.
Related reading
How to Find Out If Your Information Was Stolen in a Data Breach
Learn the free, safe way to check if your email or personal data was exposed in a data breach — and the exact steps to take next if it was.
How to Protect Your Email Account from Hackers: A Senior's Step-by-Step Guide
Learn how to secure your email account in 5 simple steps — strong passwords, two-factor authentication, and tools that catch breaches before hackers can act.
Signs Your Phone Has Been Hacked — And What to Do Right Now
7 clear warning signs your phone has been hacked, plus a step-by-step plan to secure it and protect your identity. Straightforward guide for seniors.