Fluke Data Breach (July 2026)
Fluke, the US test and measurement equipment maker, was named in a ShinyHunters extortion campaign in July 2026, and Have I Been Pwned has since verified 821,100 records holding email addresses, names, employers, job titles, physical addresses and support tickets.
- Organization
- Fluke
- Sector
- Manufacturing
- Country
- United States, WA
- Incident date
- July 1, 2026
- Disclosed
- July 15, 2026
- Records affected
- 821,000
- Attack type
- Undisclosed
- Threat actor
- ShinyHunters
- Status
- Confirmed
- Email addresses
- Employers
- Job titles
- Names
- Physical addresses
- Support tickets
- Fluke is named in a ShinyHunters pay or leak extortion campaign, per the Have I Been Pwned entry, and is listed on the group's dark web extortion portal the same day, per SOCRadar's report.
- Have I Been Pwned loads the verified records, covering 821,100 unique email addresses.
What Happened
Per the Have I Been Pwned entry, Fluke was targeted in July 2026 in a ShinyHunters pay or leak extortion campaign, and the group went on to publish more than 100GB of data it said had been taken from the company. Have I Been Pwned describes that corpus as largely corporate contact information, including over 800,000 unique email addresses along with names, phone numbers and physical addresses, plus a large collection of support cases.
SOCRadar's threat intelligence report, published on July 1, 2026, records Fluke Corporation appearing on the ShinyHunters extortion portal that day. The report notes that the group's operations have historically centered on SaaS tenant credential abuse and social engineering, but it stops short of attributing this listing to any method, and it cautions that entries on extortion sites cannot always be independently verified.
Have I Been Pwned loaded the verified breach on July 15, 2026 with a count of 821,100 records. Neither the Have I Been Pwned entry nor the SOCRadar report cites a public statement from Fluke confirming or disputing the claim. No source reviewed here states how the data was obtained, when any access began, or whether individual notifications have gone out.
What Was Exposed
6 classes of data across 821,100 records, per Have I Been Pwned, Fluke breach entry: email addresses, employers, job titles, names, physical addresses and support tickets.
Names, employers, job titles, work email addresses and support ticket history in one record give an attacker everything needed to write a convincing vendor or support follow up to a named person at a named company.
What to Do If You Are Affected
The full sequence, and what to do in what order, is in what to do after a data breach.
What Is Not Known Yet
Fluke has not publicly confirmed or disputed the leak in any source reviewed here. Nobody has said how the data was taken, over what period, or whether the people in the corpus are being notified individually.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.