2.2 million records (claimed by attacker)
The Eastman Kodak Company has confirmed it was the victim of a security breach, following a public claim by the prolific extortion group ShinyHunters. The threat actor added Kodak to its dark web leak site, alleging the theft of over 2.2 million records containing customer Personally Identifiable Information (PII) and other internal corporate data. ShinyHunters set a deadline of June 18, 2026, for Kodak to make contact before they would release the data. In response, Kodak acknowledged that an unauthorized party gained 'temporary access to a limited amount of company data' and that an investigation is underway with law enforcement. The incident highlights the continued threat posed by ShinyHunters, which has been linked to numerous large-scale data thefts.
ShinyHunters is a well-known cybercrime group that specializes in large-scale data theft and extortion. Unlike ransomware groups that encrypt data, ShinyHunters's primary model is to exfiltrate sensitive information and then demand payment to prevent its public release or sale on criminal forums. The group has a track record of successful, high-profile breaches.
In this incident, the group claims to have exfiltrated a significant volume of data from Kodak, though the company's statement suggests the breach was more limited. The discrepancy is common in such incidents, as the victim organization seeks to manage public perception while the attacker aims to maximize pressure.
While the specific attack vector against Kodak has not been disclosed, ShinyHunters has recently been associated with exploiting misconfigured Salesforce environments and zero-day vulnerabilities in enterprise software, such as a recent flaw in Oracle's PeopleSoft.
Based on ShinyHunters' recent TTPs, the attack on Kodak likely followed one of these patterns:
T1190 - Exploit Public-Facing Application): The group may have exploited a known or zero-day vulnerability in one of Kodak's internet-facing enterprise applications (e.g., CRM, ERP systems).T1078 - Valid Accounts): The attackers may have obtained credentials for a Kodak employee or a third-party contractor, allowing them to log in and access sensitive data repositories.Once inside, the group's objective is straightforward: data exfiltration (T1048 - Exfiltration Over Alternative Protocol). They identify high-value data stores, compress the information, and transfer it to their own infrastructure.
If ShinyHunters' claim of 2.2 million records is accurate, the impact on Kodak could be substantial. The potential consequences include:
No specific Indicators of Compromise (IOCs) were provided in the source articles.
To hunt for activity similar to a ShinyHunters breach, security teams should look for:
Cloud Audit Logs (e.g., Salesforce)/services/data/vXX.X/queryKodak confirmed the breach on the June 18 deadline and engaged external cybersecurity experts for the ongoing investigation.
Eastman Kodak Company officially confirmed the data breach on June 18, the deadline set by ShinyHunters for data release. The company reiterated that unauthorized access was limited and contained. Kodak has notified law enforcement and is now also working with external cybersecurity experts to investigate the incident, providing more detail on their incident response efforts.
ShinyHunters posts a claim against Kodak on its dark web leak site, setting a June 18 deadline.
Kodak issues a statement confirming a security incident and an ongoing investigation.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.