Data breach
Kendall Hunt
- Records
- 441,185
- Breach date
- 18 September 2026Estimated
- Added
- 27 September 2026
What was exposed
5 types of data
- Email addresses441,185
- Names415,854
- Phone numbers26,968
- Street addresses17,980
- Dates of birth1,096
About this breach
The ransomware group INC Ransom has claimed a cyberattack on Kendall Hunt Publishing Company, an educational publisher headquartered in Dubuque, Iowa.
According to Ransomware.live, the group added www.kendallhunt.com to its leak site on September 18, 2026, and threatened to publish stolen data unless the company opened negotiations. The investigation team estimates the incident involved about 441,185 records, with an estimated attack date of September 18, 2026.
Kendall Hunt, founded in 1944, publishes science, mathematics, and gifted curricula for grades PreK-12 and works with authors, educators, and school districts across the country. As of September 26, 2026, the company had not publicly confirmed the breach, and no detailed company notice or major news coverage of the incident was found in sources reviewed. The only public account of what was taken comes from the attackers themselves.
Limited public reporting: As of September 26, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach: approximately 441,185 email addresses, 415,854 names, 26,968 phone numbers, 17,980 street addresses, 1,096 DOBs.
Because the company has not issued its own notice, the exact source and composition of these records cannot be independently confirmed. The attackers' listing did not itemize the files.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
For people in the dataset, the exposure of a name, email address, phone number, and home address creates a serious phishing risk. Criminals can use this information to send convincing messages that reference Kendall Hunt, textbook orders, royalties, or course materials, and trick recipients into handing over passwords or payment details.
What Should You Do If You Were Affected?
Watch your email for messages claiming to come from Kendall Hunt, its online platforms, or a "breach support" team. Verify any such message by contacting the company through phone numbers or addresses listed on its official website, not through links in the message.
Change your Kendall Hunt account password and enable multi-factor authentication where available. If you reused that password on other sites, change it there too.
Check your credit reports for accounts or inquiries you do not recognize. You can request free reports from the three major credit bureaus at AnnualCreditReport.com.
Consider placing a fraud alert or a credit freeze with the bureaus, especially if you believe your Social Security or driver's license number was in the affected data. A fraud alert is free and makes lenders take extra steps to verify your identity.
Monitor your bank and email accounts for unusual activity, and be wary of unexpected calls or texts referencing textbook orders, invoices, or royalties.
If you receive official notification from Kendall Hunt, follow the steps it provides and keep the notice for your records.
