adt.com Listed by Lockbit5 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
adt.com was listed by the Lockbit5 ransomware group on August 23, 2026, with an undisclosed number of people potentially affected by exposure of personal data. Individuals are advised to check whether their information was involved and to take appropriate protective steps.
On August 23, 2026, the ransomware group known as Lockbit5 listed adt.com on its leak site. That listing is an accusation published by the group itself. Neither ADT nor a regulator has publicly confirmed an incident as of writing, and public detail beyond the listing remains limited. People affected and the types of data supposedly involved have not been disclosed in the material available here.
For customers and others who deal with a major home and business security brand, a leak-site claim matters because it raises conditional questions about personal and account information—even when nothing has been independently verified. What follows separates what the group asserts from what is actually established, and outlines practical steps that make sense whether or not the claim proves accurate.
What is being claimed
Lockbit5 has listed adt.com on its leak site, according to the reported headline and summary tied to that listing. The organization named is adt.com, associated with ADT, described in the available summary as a security company that offers security systems, cameras, alarms, and home automation services. The listing was reported on August 23, 2026.
The number of people affected is unknown. Data types named as exposed are not disclosed. Method of access, timing of any alleged intrusion, ransom demands, file volumes, and sample evidence are not included in the facts provided. The company’s public confirmation status is that it has not publicly confirmed the claim as of writing. In short, the public record at this stage is a named listing by a ransomware crew, not a verified inventory of a breach.
The group behind it: Lockbit5
Lockbit5 is presented here as the group attributed on the leak site. Publicly documented LockBit-branded operations have long followed a familiar extortion pattern: encrypt systems where they can, exfiltrate data when they claim to have done so, and pressure victims by threatening to publish material on a dedicated leak site if payment is not made. Affiliates have often carried out intrusions under a shared brand, with the site used both as a countdown mechanism and as a marketing channel for the crew’s claims.
Listings of this kind are claims by the attackers. Groups in this ecosystem sometimes exaggerate scale, recycle older material, or post names to increase leverage. Nothing in the facts supplied here independently proves that Lockbit5 obtained ADT data, only that the group has listed adt.com. Readers should treat every specific assertion about this victim—what was taken, when, and how—as unproven unless confirmed by the company, a regulator, or other credible independent reporting.
adt.com and its sector
ADT is widely known as a provider of security systems, monitoring, cameras, alarms, and related home and business automation services. Firms in this sector typically sit at the intersection of physical security and digital accounts: customer identities, service addresses, billing relationships, installer and partner networks, and systems that touch alarms and video. A credible compromise at such a firm would be consequential because trust in monitoring and alarm services depends on confidentiality and integrity of customer and operational information.
That sector context explains why a leak-site listing draws attention. It does not establish that ADT’s systems were entered, that monitoring was disrupted, or that any particular customer file left the company. A listing alone does not prove operational failure or describe internal security design; it only shows that a criminal group chose to name the organization in public.
What data was at risk
The facts state that data types named as exposed are not disclosed. It is therefore not possible to say from this record which, if any, categories of information were involved. Asserting a specific inventory would repeat attacker marketing as if it were an audit.
If files were taken from an organization in this sector, firms of this kind typically hold information such as customer names and contact details, service and installation addresses, account and billing records, contract or monitoring preferences, and credentials or identifiers tied to apps and portals—and may also hold employee or partner data and technical configuration related to devices and alarms. Those are sector norms, not a confirmed list for this listing. Exact contents remain unconfirmed, and the number of people who might be affected is unknown.
Why it matters
For individuals, the practical risk is conditional. If customer or account data associated with a security provider were ever exposed, common follow-on harms include targeted phishing that references real addresses or alarm services, account-takeover attempts on related logins, and fraud that misuses identity or billing details. Camera and home-automation contexts can make social-engineering messages sound more plausible. None of that means a given reader’s data is in criminal hands; it describes why people watch listings like this carefully.
For the organization, an unverified leak-site claim can still create reputational pressure, customer inquiries, and the need for careful public communication—without proving that systems failed or that data left the environment. What a listing establishes is narrow: a named accusation on a criminal site, a report date, and the absence so far of confirmed scope. What it does not establish is negligence, the success of an attack, or a verified dataset.
Steps worth taking either way
Treat the situation as a prompt to tighten basics rather than as proof that your information is already public. Prefer official ADT channels for account notices; do not trust unsolicited links or attachments that claim to relate to a “breach,” refund, or mandatory password reset. Use unique passwords and multi-factor authentication on email and on any security or home-automation apps. Watch bank and card statements for unfamiliar charges, and be skeptical of calls or messages that pressure you for remote access, payment, or personal details while invoking alarms or cameras.
If you used an email address with ADT or related services, consider changing that password where reused elsewhere and reviewing connected devices and sharing settings in any security apps you use. You can also run a free exposure scan of your email to check whether your information has surfaced in known breach data—useful as a general hygiene step, not as confirmation of this specific claim. If ADT or a regulator later publishes confirmed guidance, follow that primary advice over third-party summaries.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
icnavais.com Listed by Lockbit5 Ransomware Groupusbank.com Listed by Lockbit5 Ransomware Groupterra-petra.com Listed by Lockbit5 Ransomware Groupactua.fr Listed by Lockbit5 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the adt.com Listed by Lockbit5 Ransomware Group →
Publicly posted by lockbit5 — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.