Neogen Breach: 436K Email Addresses Leaked by ShinyHunters (2026)
In August 2026, the food and animal safety organisation Neogen was the target of a ShinyHunters "pay or leak" extortion attempt . The group later published data it claimed had been obtained from Neogen. The data consisted largely of corporate contact records and included 436k unique email addresses ...
Overview
Neogen, a food and animal safety company, was targeted in August 2026 by the ShinyHunters extortion group. When the company did not pay, the attackers published data they claimed came from Neogen’s systems. That dataset contained 435,963 unique email addresses drawn from mailing lists, employee records, and other corporate contact databases. The breach was later reported to Have I Been Pwned, making it searchable for anyone who wants to verify exposure.
This was not a theft of passwords or payment cards. It was a theft of contact data, and that distinction shapes both the risk and the response.
What Was Exposed
The leaked data consisted largely of corporate contact records. In practical terms, that means email addresses tied to real people and real organizations. Because the records came from mailing lists and employee directories, many of the addresses likely include full names, job titles, and the companies people work for. Neogen has not confirmed exactly how many records included those extra fields, but extortion dumps of this type typically carry more than just a bare address.
How the Breach Happened
ShinyHunters operates a “pay or leak” model: breach a target, demand a ransom, and publish the stolen data if the demand goes unmet. In this case, the group followed through and released the data publicly. The exact entry point has not been disclosed by Neogen. ShinyHunters has a long track record of targeting corporate contact databases, often through compromised third-party services, weak access controls, or social engineering against employees.
The Attacker
ShinyHunters is one of the most prolific extortion crews active today, with a history of high-profile leaks across retail, telecom, and SaaS companies. The group rarely deploys ransomware. Instead, it steals data and monetizes the threat of publication. That model works because reputational damage and regulatory scrutiny often cost more than a ransom, which is precisely why so many victims face a difficult decision when the demand arrives.
Risks to Affected People
An exposed email address alone will not drain a bank account. But the risk is real and often underestimated. Attackers use confirmed corporate addresses for targeted phishing, business email compromise attempts, and credential-stuffing attacks against other services where people reuse the same address. If your Neogen-linked address also appears in a future password dump, attackers can connect the two. Expect an uptick in convincing, personalized phishing emails referencing Neogen or your employer.
What to Do Right Now
- Check whether your address is in the leak at haveibeenpwned.com.
- Treat any email mentioning Neogen, invoices, or account verification with extreme suspicion. Verify senders through a separate channel before clicking.
- Enable two-factor authentication on your email account and any financial accounts tied to that address.
- Use a password manager so a leaked address never pairs with a reused password.
- If you are a Neogen business contact, warn your finance and IT teams about invoice-fraud attempts that may reference this breach.
Security Insight
Email-only breaches are frequently dismissed as low severity, but they are the raw material for the phishing and business email compromise attacks that cause the largest financial losses each year. ShinyHunters chose Neogen not because the data was sensitive in the traditional sense, but because a verified corporate contact list has resale value to fraudsters. Companies sitting on large marketing and employee contact databases should treat them as a distinct attack surface, with the same access controls and monitoring applied to customer financial data. For a broader look at how these incidents are trending, see our cybersecurity news coverage.
Further Reading
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In October 2026, the Discord server protection service Double Counter suffered a data breach attributed to a vulnerability in the Metabase analytics tool . In its disclosure notice, Double Counter advised that attackers gained access to a subset of its data. A corpus of data was subsequently publish...
In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). Golf Canada did...
In April 2026, the ShinyHunters extortion group listed Vimeo on their extortion portal as part of their "pay or leak" campaign . They subsequently published hundreds of gigabytes of data, predominantly consisting of video titles, technical data and metadata. The data also included 119k unique email ...
In March 2026, the NSFW AI companion platform Cuties AI suffered a data breach that was subsequently published to a public hacking forum . The incident exposed 144k unique email addresses along with display names, avatars, prompts and descriptions used to generate AI adult images, as well as URLs to...