Alcon Data Breach (August 2026)
ShinyHunters named the eye care company Alcon in a pay or leak extortion campaign at the start of August 2026 and then published a data set, and Have I Been Pwned verified 218,395 email addresses in it alongside names, phone numbers and postal addresses, most of them business contact records rather than consumer ones.
- Organization
- Alcon
- Sector
- Healthcare
- Country
- Switzerland
- Incident date
- August 1, 2026
- Disclosed
- August 9, 2026
- Records affected
- 218,000
- Attack type
- Undisclosed
- Threat actor
- ShinyHunters
- Status
- Confirmed
- Email addresses
- Names
- Phone numbers
- Physical addresses
- ShinyHunters lists Alcon on its leak site, claiming more than 25 million Salesforce records containing some personal information, per the listing recorded by Ransomware.live
- The deadline the group set for Alcon to make contact passes, per the text of the listing
- Have I Been Pwned loads 218,395 verified email addresses from the published data
- TechNadu reports the publication, giving the same count and describing the records as corporate contacts
What Happened
Alcon makes contact lenses, lens care products, surgical equipment and eye care pharmaceuticals. The company is headquartered in Geneva and runs a large part of its business from Texas, as TechNadu describes it.
On August 1, 2026, the ShinyHunters extortion group added Alcon to its leak site. The listing, recorded by Ransomware.live, claims "Over 25 million Salesforce records containing some PII was compromised" and gives the company until August 4 to make contact before publication. That figure is the group's own claim and nothing on this page verifies it.
The deadline passed and a data set was published. On August 9, Have I Been Pwned loaded 218,395 unique email addresses from it and marked the entry verified, which is why this report is filed as confirmed rather than as a claim. Per that entry, the data is presented as sourced from Alcon and consists largely of corporate contact fields, carrying names, phone numbers and physical addresses next to the email addresses. TechNadu, reporting on August 13 under the byline of Lore Apostol, gives the same count and the same reading of what the records are.
Alcon has published no statement that any source here records, and no regulator filing has surfaced. Nobody has said how the attackers reached the data, so the attack type stays undisclosed. The same group was behind the RingCentral breach, which RingCentral disclosed as a social engineering campaign, but that is context about the group rather than a finding about Alcon.
What Was Exposed
Four classes, per the Have I Been Pwned entry: email addresses, names, phone numbers and physical addresses. No passwords, no payment details and no health or patient records appear in the verified set, which is the single most important thing to know about a breach at a company in eye care.
What the data mostly holds is work contact records for the people and businesses Alcon deals with: optometry practices, distributors, suppliers and clinical customers. A name, a work email, a direct phone number and a business address is the starting kit for business email compromise, where an attacker writes to whoever pays the invoices in the voice of a known supplier and asks for a bank detail change. It also makes ordinary phishing much harder to spot, because the sender can name your practice, your contact and your address before asking you to do anything.
What to Do If You Are Affected
The full sequence, including what to change and in what order, is in what to do after a data breach, and the tells that separate a real supplier email from a forged one are in how to spot a phishing email.
What Is Not Known Yet
Whether the 25 million Salesforce records the group claimed bear any relationship to the 218,395 records actually published, how the attackers got in, whether Alcon will notify the people in the set, and whether any consumer or patient information was involved. The company has not commented, no notification has been filed with a regulator that has published it, and the other healthcare breaches on record here show that a company statement usually lands weeks after the data does.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.