Inter-Con Security Breach: 276K Records Exposed (2026)
In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompass...
Overview
In June 2026, the ShinyHunters hacking group launched a “pay or leak” extortion campaign against Inter-Con Security, a global security services provider. After the company failed to meet ransom demands, the group published a dataset containing 276,114 unique email addresses alongside names, physical addresses, job titles, and phone numbers. The breach was reported to Have I Been Pwned, giving affected individuals a way to verify exposure.
The leaked data appears to combine contacts, internal employees, and sales leads, making this a particularly complex incident. Unlike a typical customer database breach, this dataset may include both individuals who did business with Inter-Con and people who merely appeared in their CRM systems.
What Was Exposed
The exposed dataset includes:
- Email addresses - 276,114 unique entries
- Names - Full names associated with each email
- Phone numbers - Direct and mobile numbers
- Physical addresses - Home or business locations
- Job titles - Professional roles and organizational context
The combination of job titles with contact details is especially concerning. This creates a highly targeted phishing profile - attackers know exactly who you are, where you work, and your professional role.
How the Breach Happened
ShinyHunters operates on a “pay or leak” model. They gain access through credential stuffing, stolen API keys, or vulnerable web applications, then exfiltrate databases before demanding ransom. When victims refuse to pay, the group publishes the data on dark web forums to maximize damage.
This attack pattern is consistent with ShinyHunters’ track record of targeting companies with large CRM and HR databases. For Inter-Con, a company managing security contracts across multiple sectors, the attacker likely identified a high-value customer relationship database worth exploiting.
Account Takeover Risks
Email addresses, names, and phone numbers are the building blocks for account takeover attempts. With these details, attackers can:
- Phish convincingly - Craft emails referencing your job title and employer
- SIM swap - Use personal details to port phone numbers
- Credential stuffing - Try reused passwords across banking, social media, and email accounts
The job title data amplifies this risk. An attacker who knows you are a security manager at a facility can send a targeted spear-phishing message referencing your role. This is not a generic spam campaign - it’s precision targeting.
What to Do Right Now
If you believe your information may be in this dataset:
- Check Have I Been Pwned - Visit haveibeenpwned.com and search your email address. This is the fastest way to confirm exposure.
- Change passwords immediately - For any account where you reuse passwords, change them now to unique, strong alternatives. Prioritize email - it is the key to resetting every other account.
- Enable two-factor authentication - Turn on app-based 2FA for email, banking, and work accounts. SMS-based 2FA is less secure against SIM swapping.
- Be alert for spear-phishing - Watch for emails referencing your job title, employer, or physical address. Do not click links in unexpected messages.
- Freeze your credit - While no financial data was exposed, the combination of name, address, and phone number is enough to begin identity fraud attempts. A credit freeze adds a layer of protection.
How to Check If You’re Affected
The most reliable verification path is Have I Been Pwned. Enter the email address you used with Inter-Con Security. If the address appears in the breach notification, you are affected.
For employees, check with your IT department - they may have specific instructions or have already deployed additional monitoring.
Security Insight
This breach demonstrates that even security companies - organizations built on protecting people and assets - are vulnerable to the same extortion tactics as any other business. Inter-Con’s response, notably reporting the breach to Have I Been Pwned, is commendable, but the fact that a security firm held customer and employee data in a way that allowed a single exfiltration event to expose 276K records raises questions about internal access controls and data minimization practices. The inclusion of job titles alongside contact data is a reminder that seemingly innocuous professional metadata can significantly amplify phishing risk when combined with personal identifiers.
Further Reading
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign . Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, ...
In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group later published the data, which exposed 4.9M unique email addresses alo...
In April 2026, the hacking collective ShinyHunters claimed to have obtained data from Pitney Bowes as part of a broader extortion campaign that also named several other organisations. After negotiations allegedly failed, the group publicly released the data which included 8.2M unique email addresses...
In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including ove...