High

Inter-Con Security Breach: 276K Records Exposed (2026)

By Yazoul AI · automated

In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompass...

Overview

In June 2026, the ShinyHunters hacking group launched a “pay or leak” extortion campaign against Inter-Con Security, a global security services provider. After the company failed to meet ransom demands, the group published a dataset containing 276,114 unique email addresses alongside names, physical addresses, job titles, and phone numbers. The breach was reported to Have I Been Pwned, giving affected individuals a way to verify exposure.

The leaked data appears to combine contacts, internal employees, and sales leads, making this a particularly complex incident. Unlike a typical customer database breach, this dataset may include both individuals who did business with Inter-Con and people who merely appeared in their CRM systems.

What Was Exposed

The exposed dataset includes:

  • Email addresses - 276,114 unique entries
  • Names - Full names associated with each email
  • Phone numbers - Direct and mobile numbers
  • Physical addresses - Home or business locations
  • Job titles - Professional roles and organizational context

The combination of job titles with contact details is especially concerning. This creates a highly targeted phishing profile - attackers know exactly who you are, where you work, and your professional role.

How the Breach Happened

ShinyHunters operates on a “pay or leak” model. They gain access through credential stuffing, stolen API keys, or vulnerable web applications, then exfiltrate databases before demanding ransom. When victims refuse to pay, the group publishes the data on dark web forums to maximize damage.

This attack pattern is consistent with ShinyHunters’ track record of targeting companies with large CRM and HR databases. For Inter-Con, a company managing security contracts across multiple sectors, the attacker likely identified a high-value customer relationship database worth exploiting.

Account Takeover Risks

Email addresses, names, and phone numbers are the building blocks for account takeover attempts. With these details, attackers can:

  • Phish convincingly - Craft emails referencing your job title and employer
  • SIM swap - Use personal details to port phone numbers
  • Credential stuffing - Try reused passwords across banking, social media, and email accounts

The job title data amplifies this risk. An attacker who knows you are a security manager at a facility can send a targeted spear-phishing message referencing your role. This is not a generic spam campaign - it’s precision targeting.

What to Do Right Now

If you believe your information may be in this dataset:

  1. Check Have I Been Pwned - Visit haveibeenpwned.com and search your email address. This is the fastest way to confirm exposure.
  2. Change passwords immediately - For any account where you reuse passwords, change them now to unique, strong alternatives. Prioritize email - it is the key to resetting every other account.
  3. Enable two-factor authentication - Turn on app-based 2FA for email, banking, and work accounts. SMS-based 2FA is less secure against SIM swapping.
  4. Be alert for spear-phishing - Watch for emails referencing your job title, employer, or physical address. Do not click links in unexpected messages.
  5. Freeze your credit - While no financial data was exposed, the combination of name, address, and phone number is enough to begin identity fraud attempts. A credit freeze adds a layer of protection.

How to Check If You’re Affected

The most reliable verification path is Have I Been Pwned. Enter the email address you used with Inter-Con Security. If the address appears in the breach notification, you are affected.

For employees, check with your IT department - they may have specific instructions or have already deployed additional monitoring.

Security Insight

This breach demonstrates that even security companies - organizations built on protecting people and assets - are vulnerable to the same extortion tactics as any other business. Inter-Con’s response, notably reporting the breach to Have I Been Pwned, is commendable, but the fact that a security firm held customer and employee data in a way that allowed a single exfiltration event to expose 276K records raises questions about internal access controls and data minimization practices. The inclusion of job titles alongside contact data is a reminder that seemingly innocuous professional metadata can significantly amplify phishing risk when combined with personal identifiers.

Further Reading

Investigate Breaches Safely with NordVPN

Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.

Get NordVPN for Research

Affiliate link — we may earn a commission at no extra cost to you.

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.