Skip to content
Cyber Security Firms
ConfirmedHealthcare

Alcon Data Breach (August 2026)

ShinyHunters named the eye care company Alcon in a pay or leak extortion campaign at the start of August 2026 and then published a data set, and Have I Been Pwned verified 218,395 email addresses in it alongside names, phone numbers and postal addresses, most of them business contact records rather than consumer ones.

Disclosed Updated
Organization
Alcon
Country
Switzerland
Incident date
August 1, 2026
Disclosed
August 9, 2026
Records affected
218,000
Attack type
Undisclosed
Threat actor
ShinyHunters
Status
Confirmed
Data exposed
  • Email addresses
  • Names
  • Phone numbers
  • Physical addresses
Timeline
  1. ShinyHunters lists Alcon on its leak site, claiming more than 25 million Salesforce records containing some personal information, per the listing recorded by Ransomware.live
  2. The deadline the group set for Alcon to make contact passes, per the text of the listing
  3. Have I Been Pwned loads 218,395 verified email addresses from the published data
  4. TechNadu reports the publication, giving the same count and describing the records as corporate contacts

What Happened

Alcon makes contact lenses, lens care products, surgical equipment and eye care pharmaceuticals. The company is headquartered in Geneva and runs a large part of its business from Texas, as TechNadu describes it.

On August 1, 2026, the ShinyHunters extortion group added Alcon to its leak site. The listing, recorded by Ransomware.live, claims "Over 25 million Salesforce records containing some PII was compromised" and gives the company until August 4 to make contact before publication. That figure is the group's own claim and nothing on this page verifies it.

The deadline passed and a data set was published. On August 9, Have I Been Pwned loaded 218,395 unique email addresses from it and marked the entry verified, which is why this report is filed as confirmed rather than as a claim. Per that entry, the data is presented as sourced from Alcon and consists largely of corporate contact fields, carrying names, phone numbers and physical addresses next to the email addresses. TechNadu, reporting on August 13 under the byline of Lore Apostol, gives the same count and the same reading of what the records are.

Alcon has published no statement that any source here records, and no regulator filing has surfaced. Nobody has said how the attackers reached the data, so the attack type stays undisclosed. The same group was behind the RingCentral breach, which RingCentral disclosed as a social engineering campaign, but that is context about the group rather than a finding about Alcon.

What Was Exposed

Four classes, per the Have I Been Pwned entry: email addresses, names, phone numbers and physical addresses. No passwords, no payment details and no health or patient records appear in the verified set, which is the single most important thing to know about a breach at a company in eye care.

What the data mostly holds is work contact records for the people and businesses Alcon deals with: optometry practices, distributors, suppliers and clinical customers. A name, a work email, a direct phone number and a business address is the starting kit for business email compromise, where an attacker writes to whoever pays the invoices in the voice of a known supplier and asks for a bank detail change. It also makes ordinary phishing much harder to spot, because the sender can name your practice, your contact and your address before asking you to do anything.

What to Do If You Are Affected

The full sequence, including what to change and in what order, is in what to do after a data breach, and the tells that separate a real supplier email from a forged one are in how to spot a phishing email.

What Is Not Known Yet

Whether the 25 million Salesforce records the group claimed bear any relationship to the 218,395 records actually published, how the attackers got in, whether Alcon will notify the people in the set, and whether any consumer or patient information was involved. The company has not commented, no notification has been filed with a regulator that has published it, and the other healthcare breaches on record here show that a company statement usually lands weeks after the data does.

Sources

  1. Have I Been Pwned: Alcon
  2. TechNadu, ShinyHunters Data Leaks Expose Nearly 1 Million Brinks Home and Alcon Accounts, August 13, 2026
  3. Ransomware.live: Alcon Inc. listed by ShinyHunters
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →