Breach taxonomy
Summary
ADT became aware on April 20, 2026 of unauthorized access to certain cloud-based environments. The company terminated the access, activated its incident response plan, engaged third-party cybersecurity experts, and notified law enforcement. Investigation determined that only limited customer and prospective customer data was accessed; the company stated the incident is not reasonably likely to have a material impact on financial condition, results of operations, or ongoing business operations. Filed under Item 8.01; materiality not yet determined as of filing date.
Tagging rationale
ThreatUnknown
Filing references only 'unauthorized access' with no attribution to actor type or motive → UNKNOWN.
MethodsAccount Takeover
Filing describes 'unauthorized access to certain cloud-based environments' that the company then 'terminated'; no ransomware, malware, or exfiltration explicitly named, but cloud-environment intrusion implies credential or session compromise → ACCOUNT-TAKEOVER. Initial vector not specified.
AssetsPersonal Data
Filing states 'only limited customer and prospective customer data was accessed' — explicit confirmation that customer/prospective-customer personal data was the asset accessed → PERSONAL-DATA.
EffectsInfo Privacy LossNetwork Security
Customer and prospective-customer data was accessed without indication of operational disruption → INFO-PRIVACY-LOSS, with NETWORK-SECURITY reflecting the breach of cloud-environment controls.
Business continuityEffective
Filing states the company 'promptly took steps to terminate the unauthorized access' and 'activated its incident response plan'; no operational disruption disclosed → Effective.
Impact
Limited customer and prospective-customer data accessed (PII potentially involved), promptly contained, no operational disruption, and the company explicitly states not reasonably likely to be material → score 2.
InsuranceNot disclosed
Filing makes no mention of cyber insurance or insurance proceeds → null.
Read the original SEC filing excerpt
Item 8.01 Other Information. On April 20, 2026, ADT Inc. (“ADT” or the “Company”) became aware of unauthorized access to certain cloud-based environments. The Company promptly took steps to terminate the unauthorized access, activated its incident response plan (the “IRP”) as described in Item 1C of its Annual Report on Form 10-K for the year ended December 31, 2025, launched an investigation and engaged third-party cybersecurity experts, and notified law enforcement. Following the investigation conducted in accordance with its IRP, the Company determined that only limited customer and prospective customer data was accessed. Based on information currently available and following the processes laid out in its IRP, the Company does not believe that this incident is reasonably likely to have a material impact on the Company’s financial condition, results of operations, or ongoing business operations. The Company continues to assess the scope and impact of the incident.