Data breach
icsecurity.com
- Records
- 277,877
- Breach date
- 18 June 2026Estimated
- Added
- 24 June 2026
What was exposed
8 types of data · 2 put you at serious risk
- Email addresses277,877
- Street addresses265,645
- Names188,213
- Phone numbers184,071
- Driving licence numbers3,149
- Licence plates560
- Vehicle VINs424
- Social security numbers185
About this breach
ShinyHunters, a cyber extortion group known for large-scale data thefts, has claimed responsibility for a breach at IC Security, a US-based security services firm that operates the domain icsecurity.com. The group listed the company on its leak site on June 18, 2026, claiming to have stolen more than 2.7 million records along with internal corporate data, and threatened to publish the material unless the company met its demands. The investigation team later indexed a dataset tied to the incident containing 277,877 rows, a smaller figure than the group's public claim. As of September 25, 2026, IC Security has not publicly confirmed the breach, and detailed company notices or major news coverage remain limited in the sources reviewed.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
June 18, 2026: ShinyHunters listed IC Security on its leak site, claiming more than 2.7 million records were compromised, according to Ransomware.live and dExpose.
June 22, 2026: The deadline stated in the group's post, by which it threatened to publish the stolen data if its demands were not met.
June 24, 2026: the investigation team added the incident to its index after cataloging the exposed dataset.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses: 277,877
Names: 188,213
Street addresses: 265,645
Phone numbers: 184,071
Driver's license numbers: 3,149
Social Security numbers: 185
Vehicle VINs: 424
Vehicle license plates: 560
Not every individual is affected by every type of data listed here.
The presence of Social Security numbers and driver's license numbers is notable even at these counts, because these identifiers cannot be changed the way a password or email address can.
What Are the Potential Risks for Affected Individuals?
The most immediate risk is targeted phishing. Attackers holding a person's name, email, phone number, and street address can craft convincing messages that reference real details, making scams far more believable than generic spam.
For the people whose government identifiers were included, the risks run deeper. A Social Security number or driver's license number in criminal hands can be used to open fraudulent accounts, file fake tax returns, or attempt identity theft. These harms can surface months or years after a breach.
Because the dataset also includes vehicle VINs and plate numbers, there is some exposure of physical-world information as well. Criminals can use a home address combined with vehicle details to identify which car belongs to which household, which raises the risk of vehicle theft or break-ins for the roughly 500 or so individuals in that category.
IC Security's client base, described in industry reporting as spanning government, corporate, and critical infrastructure customers, also raises the possibility that some exposed records relate to security personnel or sensitive sites.
What Should You Do If You Were Affected?
Watch your email and phone for messages referencing IC Security or your personal details. Do not click links or call numbers in unsolicited messages. If a message seems legitimate, contact the organization through a verified channel.
Check your credit reports for accounts you do not recognize. You can place a free fraud alert or security freeze with the major credit bureaus.
If your Social Security number was exposed, consider creating an account at the IRS's Identity Protection PIN program and monitor for fraudulent tax filings.
Change passwords on any accounts tied to your IC Security email address, and enable two-factor authentication wherever it is offered.
If your driver's license number was involved, ask your state DMV about its procedures for flagging a compromised license number.
