ADT, Inc. Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do
ADT, Inc. disclosed a data breach on July 28, 2026 that occurred on April 20, 2026 and exposed the names, Social Security numbers, and full dates of birth of 5,129 people. Individuals should check their records and take protective steps if their information was involved.
When a company that holds identity details for customers or related individuals reports a breach, the immediate concern is straightforward: whether names, Social Security numbers, and dates of birth can be misused for fraud or identity theft. ADT, Inc. notified Washington residents of such an incident in a filing with the Washington State Attorney General, and the notice identifies those exact categories of information as exposed. For the people counted in that notice, the practical stakes are real even when the full technical picture remains limited in public filings.
According to the disclosure, the company reported the matter on July 28, 2026, and placed the incident itself on April 20, 2026. The filing states that 5,129 people were affected. What follows is a clear account of what the public record shows, how incidents of this kind typically unfold, and what affected individuals can reasonably do next.
What happened
ADT, Inc. notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on July 28, 2026. The notice lists name, Social Security number, and full date of birth among the information exposed. The filing puts the incident itself on April 20, 2026, and states that 5,129 people were affected.
Public detail beyond those points is limited. The filing does not describe the technical method of access, the systems involved, how long unauthorized access lasted, or whether data was confirmed as exfiltrated versus accessed. No specific threat actor is attributed in the disclosure. Readers should treat the Attorney General filing as the authoritative public summary of what ADT reported, rather than assuming additional unstated facts.
How a breach like this happens
Incidents that expose names, Social Security numbers, and dates of birth often follow familiar patterns, even when a particular case does not spell out the path used. Attackers may obtain credentials through phishing or reused passwords, exploit unpatched software, abuse compromised vendor or remote-access accounts, or move laterally once inside a network until they reach databases or document stores that hold identity records. In other cases, misconfigured cloud storage, overly broad employee access, or malware that steals files can produce the same result.
Organizations that handle customer, employee, or service-related identity data typically keep that information in systems used for billing, account management, background checks, or service delivery. Once those systems are reached, bulk export or selective copying of records can occur quickly. Detection may lag if logging is incomplete or if the activity blends with normal business traffic. None of this assigns a specific cause to the ADT matter; it only describes how breaches involving the same data types commonly develop when method details are not fully public.
About ADT, Inc.
ADT, Inc. is widely known as a provider of residential and commercial security and monitoring services. Companies in this sector typically maintain customer account information, service addresses, contact details, and identity data used for contracts, financing, employment, or regulatory compliance. They may also hold related records for employees, contractors, or household members associated with monitored properties.
A breach at an organization of this type is consequential because the data it holds is often sufficient to open accounts, file fraudulent tax returns, or impersonate someone in financial or government contexts. Security and monitoring firms sit at the intersection of physical safety and personal information; when identity fields are exposed, the harm is not limited to inconvenience. It can affect credit, tax filings, and the ability to prove identity for months or years afterward. The Washington filing does not expand on ADT’s internal systems or customer base beyond the affected count and data types named.
What data was at risk
The notice lists name, Social Security number, and full date of birth among the information exposed. Those three elements together are highly sensitive. A name paired with a full date of birth and a Social Security number is commonly used to verify identity for credit, benefits, employment, and government services.
The filing does not publicly detail every field that may have been present in the same systems, nor does it confirm whether additional categories were or were not involved. For organizations like ADT, typical holdings can also include addresses, phone numbers, email addresses, account numbers, or service history, but those items are not stated as exposed in the facts provided here. Exact contents beyond the named types remain limited to what the notice reports. Affected individuals should rely on any personal notification letter they receive for the most precise description of their own records.
Why it matters
Exposure of name, Social Security number, and full date of birth creates concrete risks. Criminals can attempt to open new credit accounts, apply for loans, file false tax returns, obtain government benefits, or create synthetic identities that blend real and fabricated details. Repairing that damage often requires credit freezes, fraud alerts, disputes with creditors, and ongoing monitoring. Even when no immediate fraud appears, the information can circulate for years.
For the organization, a breach of this kind brings notification duties, potential regulatory scrutiny, remediation costs, and reputational pressure. For the 5,129 people counted in the Washington-related notice, the impact is personal: they must decide how aggressively to lock down credit files, watch tax transcripts, and treat unsolicited contacts as potential social-engineering attempts. The gap between the April 20, 2026 incident date and the July 28, 2026 reporting date also means some individuals may have had a period of unknown exposure before formal notice arrived. Calm, prompt defensive steps matter more than speculation about unstated technical details.
Were you affected?
If you received a notice from ADT or believe you may be among the 5,129 people referenced in the Washington Attorney General filing, treat the named data types as compromised for practical purposes. Place a fraud alert or credit freeze with the major credit bureaus, review credit reports for unfamiliar accounts, and watch IRS and state tax accounts for unexpected filings. Keep any official breach letter; it may include reference numbers or offers of credit monitoring. Be cautious of follow-up calls or emails that claim to be from ADT or a government agency and ask for more personal information—those can be scams timed to the news.
Public filings do not always list every affected individual by name online. As a further check, readers can run a free exposure scan of their email to see whether their information has already surfaced in known breach data sets, then combine that result with the steps above. If you are unsure whether your household or account was included, contact ADT through official channels listed on its website or in any letter you received, and retain records of what you are told.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Chelan County, WA Data Breach Notice (Washington Attorney General)Kovack Financial, LLC Data Breach Notice (Washington Attorney General)Golden Opportunities And Local Support, LLC Data Breach Notice (Washington Attorney General)American Addiction Centers Data Breach Notice (Washington Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.