Inter-Con Security Data Breach (August 2026)
Inter-Con Security, a Pasadena-based private security contractor, was breached in June 2026, exposing 276,114 email addresses along with names, physical addresses, phone numbers, job titles and employer details.
- Organization
- Inter-Con Security
- Sector
- Professional services
- Country
- United States, CA
- Incident date
- June 18, 2026
- Disclosed
- August 5, 2026
- Records affected
- 276,000
- Attack type
- Undisclosed
- Threat actor
- ShinyHunters
- Status
- Confirmed
- Email addresses
- Employers
- Job titles
- Names
- Phone numbers
- Physical addresses
- Have I Been Pwned dates the Inter-Con Security incident to this day, per the listing.
- ShinyHunters claims the breach and alleges roughly 2.7 million stolen records, as reported by TechNadu.
- Have I Been Pwned loads the verified records into its database, per the listing.
- TechNadu reports that Inter-Con has not publicly confirmed the incident or notified affected individuals.
What Happened
Inter-Con Security was named in a ShinyHunters pay or leak extortion campaign, per the Have I Been Pwned entry, which dates the incident to June 2026. TechNadu reported that the group first claimed responsibility on June 19, 2026 and alleged the theft of roughly 2.7 million records. The volume Have I Been Pwned went on to verify is far smaller, at 276,114 unique email addresses pulled from the files the group published.
The listing states that the exposed data covers names, email addresses, physical addresses, phone numbers, job titles and employers, drawn from a combination of contacts, internal users and sales leads. TechNadu described Inter-Con as a Pasadena, California company that employs more than 40,000 people across North America, South America and Africa, supplying security guards, executive protection, emergency response and screening services to government agencies and corporate clients.
As of TechNadu's August 6, 2026 report, Inter-Con had not publicly confirmed the incident or notified affected individuals. TechNadu noted that the silence had already drawn scrutiny from a law firm examining whether the company's response met federal and state breach notification requirements. Neither the Have I Been Pwned entry nor the reporting states how the attackers got in, so the method remains undisclosed.
What Was Exposed
6 classes of data across 276,114 records, per Have I Been Pwned: Inter-Con Security breach entry: email addresses, employers, job titles, names, phone numbers and physical addresses.
A file that pairs a person's name and job title with their employer, phone number and home address is a ready-made target list for impersonation and pretext calls, which carries extra weight when many of those people staff government and corporate sites.
What to Do If You Are Affected
The full sequence, and what to do in what order, is in what to do after a data breach.
What Is Not Known Yet
Inter-Con has not said publicly how the attackers gained access, how many people it considers affected, or whether the client organizations named in the data were told. Nobody has explained the gap between the 2.7 million records claimed and the 276,114 verified.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.