breach
Kodak Breach: ShinyHunters Claims 2.2 Million Records
2026-06-17

Kodak, the 145-year-old imaging company based in Rochester, New York, has confirmed it is investigating a security incident in which attackers made off with some of its data. External cybersecurity specialists are involved, law enforcement has been notified, and the company is holding the line that only a "limited amount" of information was accessed and that operations are running normally.
The ShinyHunters extortion crew tells a rather different story. On their leak site they claim to have walked away with more than 2.2 million records of customer personal information and internal corporate data, with a deadline of 18 June 2026 before everything is published, alongside what they cheerfully describe as "several annoying digital problems" for Kodak.
A busy year for ShinyHunters
The same group has been credited with, or has claimed, a remarkable string of intrusions in 2025. Among them:
- Attacks on hundreds of Salesforce customer tenants.
- Breaches across Snowflake customer environments.
- A recent wave of intrusions tied to a zero-day in Oracle's PeopleSoft suite, hitting more than 100 organisations including the University of Nottingham.
- Named victims such as 7-Eleven, iRhythm, and the Council of Europe.
That is a lot of logos for one crew, and the pattern is starting to look less like opportunism and more like a methodical sweep of the platforms big companies depend on.
The gap between "limited" and 2.2 million
Kodak has not said how the attackers got in. What it has said is that the amount of data accessed was limited. ShinyHunters has put a specific, very unlimited-looking number on it. Both statements cannot be true, and the next few weeks of disclosure, sample dumps, and regulatory filings will probably reveal which side is closer to reality.
It is also worth noting that "limited" is doing heavy lifting in a lot of breach statements lately. It tends to mean "limited compared to everything we hold", which, for a company the size of Kodak, can still be a very large pile of records.
The common thread
Across the ShinyHunters portfolio, the recurring entry point has not been Kodak-style on-premise systems but third-party platforms and integrations: CRM tenants, data warehouses, HR and finance suites. That is where a lot of corporate data quietly lives now, often with access patterns and credential hygiene that have not quite caught up with how central these systems have become.
For Kodak, the immediate question is the scope of what was taken. For everyone else watching, the more useful question is which of their own SaaS tenants would look like a soft target if the same crew came knocking.