Inter-Con Security Data Breach Exposes Names, Emails and Phone Numbers

Published: 19 September 2026
Other Commercial data breach illustration
Breach Discovery: June 2026Breach Notification: August 2026

In June 2026, hackers linked to ShinyHunters breached Inter-Con Security and later leaked data on roughly 276,000 individuals, including names, emails, phone numbers, addresses, employers and job titles. The company began notifying affected people in August 2026. If you receive a notice, watch closely for phishing emails and scam calls, and consider monitoring your credit report as a precaution.

CompanyInter-Con Security
IndustryOther Commercial
Data Types ExposedEmail Addresses, Full Names, Physical Addresses, Phone Numbers, Job Titles, Employer Information
People Affected276,000 individuals
Attack MethodExtortion/Data Theft
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Inter-Con Security Data Breach?

Inter-Con Security has confirmed that its systems were targeted in a data extortion attack. According to the confirmed timeline, unauthorized access to its network occurred in June 2026. A group known as ShinyHunters claimed responsibility for the incident.

Unlike traditional ransomware attacks, this incident followed a “pay or leak” model. As a result, the attackers did not necessarily encrypt company systems. Instead, they reportedly stole data and threatened to publish it unless a ransom was paid.

The group later followed through on that threat. It publicly released a large cache of information it claimed came directly from Inter-Con Security’s internal records. This data reportedly included a mix of contacts, internal users, and sales leads, suggesting the attackers accessed multiple internal databases rather than a single isolated system.

Because the data was posted publicly, security researchers and monitoring services were able to review it. This is how many affected individuals may first learn their information was included. The company has since acknowledged the breach and began notifying affected parties in August 2026.

The exact method the attackers used to gain initial access has not been publicly disclosed. However, extortion groups like ShinyHunters often rely on stolen credentials, exploited software flaws, or third-party vendor weaknesses to break into corporate networks.

Who was affected?

The Inter-Con Security data breach appears to affect a broad mix of people connected to the company. This includes contacts stored in company databases, internal system users, and individuals classified as sales leads. In other words, both employees and outside individuals who interacted with the company may be impacted.

Based on currently available information, approximately 276,000 unique email addresses were included in the exposed data. This number reflects unique email addresses tied to records rather than a confirmed total of distinct individuals, though it offers a reasonable scale of the incident.

The geographic scope of those affected has not been publicly disclosed. Similarly, it is not clear whether minors are among the affected individuals. Because the data includes job titles and employer information, it seems likely that many affected people are business contacts or professionals rather than general consumers.

What Information Was Potentially Exposed?

The exposed data set is centered on contact and professional identification details rather than financial or medical records. Even so, this type of information can still be misused by cybercriminals in meaningful ways.

Based on the confirmed details of this incident, the following data types were included:

  • Email addresses
  • Full names
  • Physical addresses
  • Phone numbers
  • Job titles
  • Employer information

This combination of information is often called a “contact profile.” While it may seem less severe than a breach involving Social Security numbers, it still gives criminals enough detail to build convincing, targeted scams.

For example, a scammer who knows your name, job title, employer, and phone number can impersonate a coworker, vendor, or executive. This tactic is frequently used in business email compromise schemes and targeted phishing attacks. Because the data includes both personal and workplace details, it increases the chances of a scam sounding legitimate.

In addition, having a verified, active email address tied to a real name and phone number makes individuals more attractive targets for spam, robocalls, and social engineering attempts. Combined with public information available elsewhere, criminals could potentially piece together a fuller picture of a person’s professional life and habits.

What is the company doing?

Inter-Con Security has acknowledged the incident and stated that it is responding accordingly. As part of its response, the company began notifying individuals whose information may have been included in the exposed data.

Because the data was already published by the attackers, the company’s ability to prevent exposure was limited once the leak occurred. Instead, its response has focused on notification, internal review, and helping affected individuals understand the risk.

Going forward, organizations facing this type of extortion incident typically conduct a broader security review. This often includes strengthening network defenses, reviewing vendor access, and monitoring for further misuse of the leaked data. Affected individuals should watch for official communication directly from Inter-Con Security regarding any additional steps or protective resources.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Even though this breach did not confirm exposure of Social Security numbers, monitoring your credit report is still a smart precaution. Identity thieves sometimes combine leaked contact details with other information found elsewhere online.

You can request a free credit report from each of the three major credit bureaus. Reviewing these reports regularly helps you catch unfamiliar accounts or inquiries early. If you notice anything suspicious, report it right away to limit potential damage.

Stay Alert for Phishing and Impersonation Attempts

Because names, emails, phone numbers, and job titles were exposed, phishing risk is a top concern here. Scammers can use this information to craft messages that appear to come from a coworker, employer, or trusted contact.

Be cautious of unexpected emails or calls asking for sensitive information or urgent action. Always verify requests through a separate, trusted communication channel before responding. This is especially important for messages referencing job titles or workplace relationships, since that detail adds a false sense of legitimacy.

Be Cautious With Unsolicited Calls and Texts

Since phone numbers were included in the exposed data, affected individuals may see an increase in spam or scam calls. These calls may reference personal details to seem more convincing.

As a precaution, avoid sharing additional personal information over the phone unless you initiated the call yourself. In addition, consider using call-blocking tools or reporting repeated scam attempts to your mobile carrier.

Review Your Online Presence and Account Security

Because your name, employer, and job title are now more visible together, it’s worth reviewing what other information about you is publicly accessible online. This can help you understand your overall exposure.

It’s also a good time to update passwords, especially if you reuse them across multiple accounts. Enabling two-factor authentication wherever possible adds an extra layer of protection, even if login credentials are later exposed in a separate incident.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Browse all recent data breaches →