ADT, Inc. Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
ADT, Inc. disclosed a data breach on July 28, 2026, affecting 331,536 individuals. The breach occurred on April 20, 2026, exposing personal information; affected residents should review the Oregon Attorney General notice and monitor their accounts.
Hundreds of thousands of people may need to treat their personal information as exposed after ADT, Inc. reported a data breach that the company says occurred in April 2026. When a large security and monitoring firm notifies regulators that personal information was involved, the practical stakes are straightforward: affected individuals can face higher risk of identity misuse, targeted scams, and account takeover attempts that rely on details tied to their real names and contact history.
According to a filing reported to the Oregon Department of Justice on July 28, 2026, ADT, Inc. notified Oregon residents of the incident. The same filing places the incident itself on April 20, 2026, and states that 331,536 people were affected. Public detail beyond that notice remains limited, but the scale alone makes the event material for anyone who has been an ADT customer, prospect, or household contact whose data the company held.
Inside the incident
ADT, Inc. submitted a data breach notice reflected in Oregon Attorney General reporting, with the filing dated July 28, 2026. The notice identifies the incident date as April 20, 2026, and reports 331,536 people affected. The breach notification describes the exposed material as personal information. The public record provided here does not describe how the incident was discovered, whether systems were encrypted or copied, how long unauthorized access lasted, or which technical pathway was used.
There is no attributed threat group in the available facts, and no confirmed list of every data field beyond the broad category of personal information. The gap between the stated incident date in April and the July reporting date is noted in the filing timeline; reasons for that interval are not explained in the summary at hand. Readers should treat only the dated notice, the headcount, and the “personal information” characterization as established from this disclosure.
How a breach like this happens
Incidents described in regulatory notices as involving personal information often follow familiar patterns, even when a specific method is not published. Attackers may obtain credentials through phishing or reused passwords, exploit unpatched remote access software, or abuse a compromised vendor account that already has legitimate pathways into customer databases. Once inside, they commonly search for directories or applications that store names, addresses, account identifiers, and related contact data, then copy that material for later fraud or resale.
Other common paths include misconfigured cloud storage, malware on an employee workstation that leads to broader network access, or theft of backup files. None of these scenarios is confirmed for this ADT notice; they are general background on how organizations of this type typically experience unauthorized access to personal records. Without a published forensic narrative, it is not possible to say which pattern, if any, applies here.
Who is ADT, Inc.?
ADT, Inc. is widely known as a provider of residential and commercial security, alarm monitoring, and related home and business protection services in the United States. Companies in this sector routinely maintain customer accounts, service addresses, billing relationships, emergency contacts, and operational records needed to install equipment, monitor signals, and respond to alerts. That operational model means they often hold concentrated sets of identity and household data for large numbers of people.
A breach affecting a firm in this position is consequential because the same data that supports legitimate monitoring and customer service can also help criminals craft convincing fraud. Impersonation of a security provider, fake “alarm” or “account suspension” calls, and attempts to change monitoring or billing details are recurring risks when personal information from such organizations is exposed. The Oregon filing does not itself prove any particular secondary crime wave; it does establish that a substantial population was included in the company’s notification count.
What data was at risk
The breach notification, as summarized in the available facts, names the exposed category as personal information. It does not itemize fields such as Social Security numbers, driver’s license numbers, financial account numbers, or precise contact elements in the material provided here. Exact contents beyond that label are therefore unconfirmed in this record.
Organizations like ADT typically hold data needed to identify customers and service locations—names, addresses, phone numbers, email addresses, account numbers, and sometimes payment or identity-verification details. Those are ordinary holdings for the sector, not a confirmed inventory of what left ADT’s control in this incident. Until a fuller notice or official clarification lists specific elements, affected people should assume that whatever personal information ADT associated with their relationship could be in scope, without treating any single sensitive field as proven fact from this summary alone.
The real-world impact
For individuals counted among the 331,536 affected, the main risks are practical rather than abstract. Personal information can be used to open fraudulent accounts, reset passwords on unrelated services, or support social-engineering calls that reference a real security provider or home address. Even limited data can make phishing more believable. People who shared household or emergency-contact details with a monitoring company may also find relatives drawn into follow-on scams.
For ADT, a notice of this size carries regulatory, operational, and trust consequences: mandatory notifications, potential inquiries from state authorities, customer support load, and the need to harden systems and communicate clearly. The facts do not assign legal fault or describe remediation steps already taken. They do establish a large affected population and a multi-month span between the stated incident date and the Oregon filing date, which is relevant context for anyone tracking their own exposure window.
What to do if you're exposed
If you have reason to believe you are among those notified—or you are an ADT customer and receive an official letter—start with the basics. Read any notice carefully for the exact data categories ADT lists for you; those details govern what to monitor. Place a fraud alert with the major credit bureaus if sensitive identity data may be involved, and consider a credit freeze if you want stricter control over new credit lines. Review bank, card, and email accounts for unfamiliar activity, and treat unsolicited calls or texts about alarms, refunds, or “secure your ADT account” links with skepticism—verify through official channels you already trust.
Change passwords on related accounts, enable multi-factor authentication where available, and keep records of any notification dates. If you are unsure whether your email address has appeared in known breach datasets generally, you can run a free exposure scan of your email to check whether your information has surfaced in catalogued breach data, then prioritize monitoring accordingly. Official guidance from your state attorney general or the Federal Trade Commission on identity theft recovery remains the best next step if you see concrete signs of misuse.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Abbott Cancer Diagnostics Data Breach Notice (Oregon Attorney General)Aesto, LLC Data Breach Notice (Oregon Attorney General)Wilmer Cutler Pickering Hale and Dorr LLP Data Breach Notice (Oregon Attorney General)JRK Property Holdings, Inc. Data Breach Notice (Oregon Attorney General)Latest breaches
Read GalaxyWarden’s full analysis of the ADT, Inc. Data Breach Notice (Oregon Attorney General) →
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.