American Tower Data Breach (2026): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
American Tower disclosed a data breach on June 12, 2026, affecting 217,000 people whose email addresses, job titles, names, phone numbers, and physical addresses were exposed. Individuals should check whether their information was included and take steps to protect themselves.
What happened
In June 2026 American Tower became the subject of a ShinyHunters extortion campaign described as following a “pay or leak” pattern. The group later published material it alleged had been taken from the company. The published material is reported to contain more than 200,000 unique email addresses linked to employees, contractors, customers, and leads, together with names, job titles, phone numbers, and physical addresses. No further technical details on the intrusion method, the exact volume of files, or confirmation of the data’s origin have been disclosed in available reporting.
Who is shinyhunters?
ShinyHunters is a threat actor known publicly for conducting data theft operations against a range of organisations and then attempting to extort payment in exchange for not releasing the material. The group has a documented pattern of posting sample data on leak sites or forums when demands are not met. Its listings are treated as claims until independently verified; in this case the group asserts that the American Tower records were obtained through its own actions, but no additional confirmation of that attribution has been published.
About American Tower
American Tower operates telecommunications infrastructure, principally cellular towers and related facilities, and maintains business relationships with mobile-network operators, contractors, and other service providers. Organisations of this type routinely store contact information for employees, vendors, and prospective clients in order to manage site access, maintenance contracts, and regulatory compliance. A breach involving such records can therefore expose operational contact points across a distributed physical network.
What data was at risk
The published dataset is reported to include email addresses, names, job titles, phone numbers, and physical addresses. The precise scope of any additional fields, the completeness of the records, or whether other categories of information were also present remains undisclosed. Organisations in this sector commonly hold similar contact directories; without an official statement from American Tower the exact contents cannot be confirmed beyond the types already referenced in public reporting.
What's at stake
Individuals whose details appear in the published material face an increased likelihood of receiving unsolicited messages, including phishing attempts that use known job titles or site locations to appear credible. For the organisation, exposure of contractor and customer contact lists can complicate routine business communications and may require additional verification steps for future interactions. No evidence of follow-on credential misuse or system-level compromise has been reported in connection with this incident.
Were you affected?
Anyone who has had professional contact with American Tower or its partners can check whether their email address appears in known public breach repositories by using a free exposure-scanning service. Practical first steps include monitoring email accounts for unexpected messages, avoiding clicking links in unsolicited correspondence that reference the company, and enabling multi-factor authentication on any accounts that reuse the exposed email address.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Sysco Data Breach (2026)Ralph Lauren Data Breach (2026)Madison Square Garden Sports Data Breach (2026)DentaQuest Data Breach (2026)Latest breaches
Read GalaxyWarden’s full analysis of the American Tower Data Breach (2026) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.