ADT discloses second breach in two months after partner credentials stolen

Organization
ADT Inc.
Exploit
Credential Compromise
Industry
Home Security

ADT, the residential and commercial security provider, disclosed in a Form 8-K filed with the U.S. Securities and Exchange Commission on October 7, 2024 that an unauthorized actor had accessed its network using credentials obtained through a third-party business partner. The company said it detected the intrusion in early October and moved to shut the access down.

According to the filing and subsequent reporting, the attacker exfiltrated certain encrypted internal data associated with ADT employee user accounts. ADT said that based on its investigation to that point it did not believe customers' personal information had been taken, and that customer security systems had not been compromised.

ADT said it notified the affected business partner, engaged outside cybersecurity specialists and worked with federal law enforcement. The company acknowledged that the countermeasures it deployed to contain the intrusion disrupted some of its information systems and business operations while it investigated and restored them.

The incident followed a separate disclosure roughly two months earlier, in August 2024, when ADT said unauthorized actors had accessed databases holding customer order information. BleepingComputer reported that about 30,800 customer records containing email addresses, phone numbers, postal addresses, user IDs and purchase details were leaked on a hacking forum in that earlier case.

As of the October reporting, no ransomware group or other threat actor had publicly claimed responsibility for the second intrusion, and ADT had not quantified how many employee accounts were involved.

Sources