Inter-Con Security Hit by ShinyHunters Extortion Attack, Exposing 276K Email Addresses
In June, cybercriminal group ShinyHunters targeted Inter-Con Security in a "pay or leak" extortion campaign, resulting in the exposure of 276,000 unique email addresses alongside names, physical addresses, and other sensitive data. The leaked information was subsequently published, with 44% of the affected emails already linked to LinkedIn profiles, increasing the risk of targeted phishing or identity-related attacks.
The breach highlights the growing threat of double-extortion tactics, where attackers not only encrypt data but also threaten to release it publicly unless a ransom is paid. While the full scope of the compromised data remains under review, the incident underscores vulnerabilities in third-party security practices and the potential for widespread downstream impacts, particularly for individuals whose personal details were exposed.
Source: https://www.linkedin.com/feed/update/urn:li:activity:7490916105138597888
Inter-Con Security cybersecurity rating report: https://www.rankiteo.com/company/interconsecurity
"id": "INT1785975818",
"linkid": "interconsecurity",
"type": "Breach",
"date": "6/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '276,000 unique email addresses',
'industry': 'Security Services',
'name': 'Inter-Con Security',
'type': 'Organization'}],
'data_breach': {'data_exfiltration': 'Yes (published publicly)',
'number_of_records_exposed': '276,000',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (personally identifiable '
'information)',
'type_of_data_compromised': ['Email addresses',
'Names',
'Physical addresses',
'Other sensitive data']},
'description': 'In June, cybercriminal group ShinyHunters targeted Inter-Con '
"Security in a 'pay or leak' extortion campaign, resulting in "
'the exposure of 276,000 unique email addresses alongside '
'names, physical addresses, and other sensitive data. The '
'leaked information was subsequently published, with 44% of '
'the affected emails already linked to LinkedIn profiles, '
'increasing the risk of targeted phishing or identity-related '
'attacks.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'data exposure',
'data_compromised': '276,000 unique email addresses, names, '
'physical addresses, and other sensitive data',
'identity_theft_risk': 'Increased risk of targeted phishing or '
'identity-related attacks'},
'lessons_learned': 'Highlights the growing threat of double-extortion tactics '
'and vulnerabilities in third-party security practices.',
'motivation': 'Financial gain (extortion)',
'post_incident_analysis': {'root_causes': 'Vulnerabilities in third-party '
'security practices'},
'ransomware': {'data_exfiltration': 'Yes'},
'threat_actor': 'ShinyHunters',
'title': 'Inter-Con Security Hit by ShinyHunters Extortion Attack',
'type': 'Extortion'}