Full Report
In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompassed a combination of contacts, internal users and leads.
Analysis Summary
# Incident Report: Inter-Con Security Data Breach (ShinyHunters Extortion)
## Executive Summary
In June 2026, Inter-Con Security was targeted by the threat actor group ShinyHunters in a "pay or leak" extortion campaign. Following a failed extortion attempt, the group published a database containing 276,100 unique records including PII of contacts, internal users, and leads.
## Incident Details
- **Discovery Date:** August 5, 2026 (Public indexing/HIBP addition)
- **Incident Date:** June 2026
- **Affected Organization:** Inter-Con Security
- **Sector:** Security Services / Private Security
- **Geography:** Global (Headquartered in Pasadena, CA)
## Timeline of Events
### Initial Access
- **Date/Time:** June 2026
- **Vector:** Unknown (ShinyHunters typically utilize credential stuffing or cloud storage misconfigurations)
- **Details:** The threat actor gained access to internal systems containing CRM or employee directory data.
### Lateral Movement
- **Details:** Information not publicly disclosed in the provided source.
### Data Exfiltration/Impact
- **Details:** Approximately 276,100 unique email addresses and associated PII were exfiltrated. The group threatened the organization with a "pay or leak" demand. When the demand was likely not met, the data was published on the dark web/clearnet forums.
### Detection & Response
- **How it was discovered:** Public announcement by threat actor "DarkWebInformer" on X (formerly Twitter) and subsequent data dump.
- **Response actions taken:** Data was verified and added to Have I Been Pwned (HIBP) for public notification on August 5, 2026.
## Attack Methodology
- **Initial Access:** Extortion-based infiltration (Likely cloud-based or API-driven based on actor profile).
- **Persistence:** Not disclosed.
- **Exfiltration:** High-volume data export of database tables.
- **Impact:** Data exfiltration and public extortion.
## Impact Assessment
- **Financial:** Potential regulatory fines and costs associated with credit monitoring for affected employees/leads.
- **Data Breach:** High. 276,100 unique email addresses, full names, physical addresses, job titles, and phone numbers.
- **Operational:** Minimal disruption to physical security operations reported, but significant impact on HR and IT Security workflows.
- **Reputational:** High public impact due to the company's nature as a security provider being breached by a high-profile extortion group.
## Indicators of Compromise
- **Network indicators:** hxxps[://]x[.]com/DarkWebInformer/status/2069536119545540871 (Threat actor announcement link)
- **File indicators:** Database export containing Inter-Con contact fields.
- **Behavioral indicators:** Large-scale data egress to non-standard external IPs (typical of ShinyHunters activity).
## Response Actions
- **Containment measures:** Information not provided in the source; standard protocol would involve credential resets and cloud instance isolation.
- **Eradication steps:** Internal audit of data storage permissions.
- **Recovery actions:** Notification of affected parties and integration with breach monitoring services (HIBP).
## Lessons Learned
- **Key takeaways:** Even security-focused organizations are vulnerable to supply chain or cloud-based data theft. Extortion groups are increasingly bypassing ransomware (encryption) in favor of direct data theft ("pay or leak").
- **What could have been done better:** Implementation of stricter Data Loss Prevention (DLP) controls to flag the mass export of contact lists.
## Recommendations
- **Identity Management:** Enforce mandatory Multi-Factor Authentication (MFA) across all internal and cloud-based applications.
- **Data Protection:** Encrypt PII at rest within databases and implement strict Access Control Lists (ACLs) for "Lead" and "Contact" databases.
- **Monitoring:** Implement anomaly detection for large-scale data exfiltration and monitor the dark web for mentions of corporate credentials or data leaks.