Data breach
Pitney Bowes
- Records
- 9,489,178
- Breach date
- 18 April 2026Estimated
- Added
- 23 April 2026
What was exposed
4 types of data · 2 more reported
- Names9,489,178
- Email addresses8,313,261
- Phone numbers7,039,432
- Street addresses6,113,153
- EmploymentReported, not counted
- Job titlesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Logistics and mailing technology company Pitney Bowes has been drawn into a wide-ranging extortion campaign after a threat actor known as ShinyHunters claimed to have stolen millions of customer records from the company's Salesforce customer relationship management environment. According to reporting by The Register, Pitney Bowes confirmed that a phishing attack compromised an employee email account, giving an intruder access to records tied to business customer accounts and contacts. The company says the activity did not extend into other Pitney Bowes systems.
Our investigation team estimates that the dataset tied to this listing contains roughly 9.5 million records, including about 8.3 million email addresses, 7 million phone numbers, and 6.1 million street addresses, alongside names for the full set. The listing was indexed on April 23, 2026, with an estimated attack date of April 18, 2026. ShinyHunters, which has claimed a series of similar attacks against large organizations in recent months, listed Pitney Bowes on its leak site with a pay-or-leak demand, according to ransomware.live.
April 9, 2026: Pitney Bowes identified unauthorized access to records in its Salesforce environment. The company said the intrusion happened the night before and stemmed from a phishing attack that compromised an employee email account, according to statements reported by The Register.
April 18, 2026: ShinyHunters listed Pitney Bowes on its leak site with an extortion demand, giving the company an April 21 deadline before releasing data, per ransomware.live.
April 27, 2026: Independent breach trackers confirmed the dataset, reporting roughly 8.2 million unique email addresses along with names, phone numbers, and physical addresses, as covered by The Register and reflected in Mozilla Monitor.
April 29, 2026: Pitney Bowes told The Register it had notified affected business customers directly, engaged cybersecurity experts and law enforcement, and implemented additional access controls, expanded monitoring, and targeted employee training.
What Information Was Compromised?
Our analysis found the following data types in this breach: names, email addresses, phone numbers, and street addresses.
The Register's reporting adds that a smaller subset of the leaked data involved company employment records, including job titles. Mozilla Monitor also lists job titles among the compromised data types. No passwords were reported as part of this dataset.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the exposed data combines names, contact details, and physical addresses, the most immediate risk is targeted phishing. Attackers who know your name, email, phone number, and employer details can craft convincing emails, text messages, or phone calls that appear legitimate, sometimes impersonating Pitney Bowes, a shipping carrier, or another vendor.
Fraudsters may also use leaked addresses and phone numbers to lend credibility to scam attempts, such as fake delivery notices or account verification calls. Since passwords were not part of the reported dataset, direct account takeover risk from this breach alone appears lower than in credential leaks, but criminals often combine data from multiple breaches, so any exposure increases overall risk. Affected business contacts may face a heightened risk of business email compromise schemes aimed at their organizations.
What Is Pitney Bowes Doing in Response?
In statements reported by The Register on April 29, 2026, the company said it secured the environment immediately after discovering the access, revoked the compromised account, and engaged cybersecurity experts and law enforcement. Pitney Bowes stated that its investigation found no evidence the activity spread to other systems and no indication that sensitive personal data was accessed, and that it notified affected business customers directly. The company also said it added access controls, expanded monitoring, and rolled out targeted employee training.
What Should You Do If You Were Affected?
If you believe your information was involved, take these steps:
Treat unsolicited emails, calls, or texts referencing Pitney Bowes, shipping, or account issues with suspicion. Verify any request by contacting the company through its official website rather than through links or numbers in the message.
Be alert to phishing attempts that reference your name, address, or job details. Attackers use leaked contact data to make messages feel personal.
Consider using an email masking service for future signups, which limits how much of your real address is exposed in incidents like this.
Limit where you share your phone number, and enable multi-factor authentication on accounts that offer it.
