Data breach
Kemper Corporation
- Records
- 1,096,869
- Breach date
- 11 April 2026Estimated
- Added
- 20 April 2026
What was exposed
6 types of data · 1 puts you at serious risk
- Names1,096,869
- Street addresses339,272
- Phone numbers321,844
- Email addresses158,466
- Dates of birth28
- Social security numbers14
About this breach
ShinyHunters, a hacking group known for extorting large companies, posted data allegedly stolen from Kemper Corporation on its dark web leak site in mid-April 2026, after ransom negotiations reportedly failed. The group claims it pulled the data from Kemper's Salesforce account through social engineering as part of a wider campaign against hundreds of organizations. According to our investigation team, roughly 1.1 million records tied to the breach have been indexed, including names, email addresses, phone numbers, and street addresses. Kemper, an insurance holding company based in Chicago, has confirmed it is aware of the incident and says it is investigating with outside cybersecurity experts.
April 15, 2026: ShinyHunters posted alleged Kemper Corporation files on its dark web site after reported negotiations failed, according to a press release from the law firm Edelson Lechtzin LLP.
April 21, 2026: Edelson Lechtzin LLP announced it was investigating data privacy claims arising from the breach.
What Information Was Compromised?
Our analysis found the following data types in this breach: names (about 1.1 million), email addresses (about 158,000), phone numbers (about 322,000), street addresses (about 339,000), Social Security numbers (14 records), and dates of birth (28 records).
Reporting adds further detail. ShinyHunters claims to hold at least 29 GB of data and more than 13 million Kemper records from the company's Salesforce account, including internal directory data and Stripe payment logs containing customer names and transaction amounts. TechNadu reported that leaked datasets also included partial payment card data, such as the last four digits, expiry dates, and card brands. A class action firm investigation announcement said exposed material may also include internal corporate documents and employee training materials.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of names, addresses, phone numbers, and email addresses is enough to fuel targeted phishing and smishing attacks, where scammers pose as Kemper, insurers, or banks using details that make their messages look legitimate. Because ShinyHunters ultimately leaked the data publicly rather than only selling it privately, the risk of that information circulating among fraud groups is higher than in extortion cases where the data is withdrawn.
Any Social Security numbers or payment card details, even partial ones, raise the stakes further. The Jaszczuk firm reports that plaintiffs in recently filed class actions allege compromised data included Social Security numbers, insurance policy information, and claims data. Individuals whose numbers were exposed face a heightened risk of identity theft and fraudulent account openings, while cardholders should watch for unauthorized charges.
What Is Kemper Corporation Doing in Response?
Kemper has confirmed it is aware of the cybersecurity incident and launched an investigation, according to the Edelson Lechtzin announcement. The company reported that it engaged third-party cybersecurity experts and notified law enforcement. The investigation remains ongoing, and the full scope of what was taken has not been publicly confirmed by the company.
At least three class action lawsuits have been filed against Kemper in the U.S. District Court for the Northern District of Illinois by former employees, alleging the company failed to implement reasonable cybersecurity safeguards. Kemper has not publicly confirmed every data type alleged in those complaints.
What Should You Do If You Were Affected?
Be skeptical of unexpected calls, texts, or emails that reference Kemper or insurance matters, and never share account numbers or codes with unsolicited contacts.
Review bank, credit card, and insurance account statements for charges or changes you did not make.
Check your credit reports for free at annualcreditreport.com and place a fraud alert or security freeze with the three credit bureaus if you have reason to believe your Social Security number was exposed.
Keep any notification letters or emails you receive from Kemper, as they may confirm exactly what data of yours was involved.
In the news
- PR Newswire, Edelson Lechtzin LLP investigation announcementprnewswire.com (opens in a new tab)
- TechNadu, coverage of the ShinyHunters extortion campaigntechnadu.com (opens in a new tab)
- Jaszczuk PC, summary of class action filingsjaszczuk.com (opens in a new tab)
- Stueve Siegel Hanson, breach investigation pagestuevesiegel.com (opens in a new tab)
