Eastman Kodak, the 138-year-old imaging and materials company, spent the week of June 15, 2026 doing something few companies want to do in public: negotiating, in real time, with an extortion crew that had just posted its name to a dark-web leak site. The group, ShinyHunters, claimed it had pulled more than 2.2 million records of customer and internal corporate data out of Kodak’s systems. It gave the company three days to respond before the data went public.
Kodak is not an isolated case. It is the latest name on a leak site that, by mid-2026, had already logged well over 100 victims in a single year, according to multiple breach trackers. The Kodak incident is small by the standards of ShinyHunters’ own 2026 campaign, where single claims have run past 275 million records. But it is a useful case study, because it shows exactly how the group’s playbook now works: no ransomware payload, no encrypted files, just a public deadline and a bet that reputational risk will do the negotiating for them.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What ShinyHunters Claims Happened to Kodak
On June 15, 2026, ShinyHunters added kodak.com to its dark-web data leak site, according to breach-tracking service ransomware.live, which logged the posting at 14:24 UTC. The listing described “over 2.2 million records containing customer PII and other internal corporate data,” and set a deadline: reach out by June 18, 2026, or the group would publish the data. Cybernews was among the first outlets to report the claim, framing it as part of ShinyHunters’ broader “pay or leak” campaign against enterprise targets.
The listing itself reads like dozens of others the group has posted this year. Here is the tracked entry, reproduced from the leak-site monitoring record:
Group: ShinyHunters
Victim: kodak.com
Discovered: 2026-06-15 14:24 UTC
Est. attack date: 2026-06-15
Description: Over 2.2 million records containing customer PII
and other internal corporate data was compromised. This is a
final warning to reach out by 18 June 2026 before we leak.
Kodak has not confirmed the 2.2 million figure. That distinction matters. In extortion cases like this one, the number that circulates in headlines is almost always the attacker’s own claim, not a verified count from the victim, a regulator, or an independent forensic firm. Kodak’s public statements, discussed below, describe something narrower than what ShinyHunters is advertising.
Timeline: How the Kodak Extortion Attempt Unfolded
Stripped of commentary, the public timeline is short and easy to follow. It also shows how little time companies get to respond once a leak-site posting goes live.
- June 15, 2026, 14:24 UTC: ShinyHunters lists kodak.com on its dark-web leak site, claiming 2.2 million-plus records.
- June 15-17, 2026: Security outlets including Cybernews and Dexpose pick up the claim, while Kodak has not yet issued a public statement.
- June 18, 2026: The attackers’ self-imposed deadline arrives. The same day, Kodak confirms to BleepingComputer that it is investigating unauthorized access to a limited amount of data, and calls the incident contained.
- Late June 2026: Coverage from Malwarebytes and other outlets frames Kodak as the latest in a long line of 2026 leak-site victims, without reporting a confirmed mass data dump.
- July 2026: Broader roundups, including CM-Alliance’s monthly breach report, list Kodak alongside dozens of other June 2026 incidents, cementing it as one data point in a very busy month for extortion news rather than a standalone crisis.
Kodak’s Official Response: “Limited” and “Contained”
Kodak confirmed the incident to BleepingComputer on June 18, 2026, the same day the attackers’ deadline landed. The company said it was investigating after an unauthorized third party briefly accessed a limited amount of company data. Kodak characterized the incident as contained and said it did not threaten the company’s systems or operations. It brought in outside cybersecurity specialists to assist the investigation, according to the same report.
That is a materially different story than “2.2 million records compromised.” Companies facing leak-site extortion routinely downplay scope in early statements, partly because full forensic scoping takes weeks, and partly because confirming an attacker’s number hands them leverage. Malwarebytes noted that Kodak was simply “the latest organization” to land on ShinyHunters’ site, a phrase that captures how routine these incidents have become by mid-2026.
What isn’t in the public record, as of this writing, is a confirmed mass publication of Kodak data after the June 18 deadline passed. That doesn’t mean the data wasn’t leaked in a smaller or quieter form, only that no outlet has documented a full dump. It’s a pattern that shows up across several 2026 ShinyHunters cases: a loud deadline, a company statement that stops short of confirmation, and then silence rather than a dramatic follow-through.
Who Is ShinyHunters? A Group With 400+ Victims Since 2020
ShinyHunters has been active since 2020, and according to security vendor DoControl, it has breached more than 400 organizations across retail, technology, finance, aviation, and automotive sectors over that period. What sets 2026 apart is the pace. Breach-tracking site the Hunters Ledger counted 36 named archives on the group’s clearnet leak site as of April 24, 2026, while Cybernews put the combined clearweb-and-Tor total closer to 40 organizations that same month. By July 6, 2026, The Register reported the leak site listed 86 victims since January, with a caveat that the real number is likely higher, since organizations that pay are typically removed from the list. By late July, blog coverage from Paubox put the estimated cumulative victim count at 132, naming Kodak alongside Instructure’s Canvas platform and retailer JCPenney.
The FBI has taken formal notice. On May 15, 2026, the Bureau’s Internet Crime Complaint Center issued PSA IC3-PSA-2026-0515, warning specifically about ShinyHunters activity against learning institutions. It’s an advisory rather than an enforcement action, and no 2026 arrests of ShinyHunters members had been publicly announced as of the Kodak incident.
Why Kodak Fits the Group’s Target Pattern
ShinyHunters doesn’t appear to pick targets by industry. Its 2026 victim list spans a learning-management platform, a medical device maker, a dating app conglomerate, and now a 138-year-old imaging and materials company. What connects them is exposure: large stores of customer records sitting behind enterprise software, cloud platforms, or SaaS integrations that are easier to compromise at scale than to defend at scale. Kodak, a mid-sized public company with a real customer base but nowhere near the security budget of a hyperscaler, is a fairly typical profile for the group’s mid-tier targets, sitting below the scale of its Instructure or Oracle PeopleSoft campaigns but above the smallest victims on its list.
The Data at Stake: What 2.2 Million Records Could Contain
ShinyHunters’ own description names two categories: customer personally identifiable information and internal corporate data. Neither Kodak nor the attackers have published a detailed schema of what fields are involved, so specifics like Social Security numbers, payment data, or employee records remain unconfirmed. That ambiguity is itself part of the extortion tactic. A vague, large-sounding claim generates pressure without requiring proof, and victims are reluctant to speculate publicly about worst-case contents before their own forensic review is complete.
This is a consistent feature of the group’s 2026 cases. In the Medtronic incident, ShinyHunters claimed 9 million records when it listed the medical device maker on April 18, 2026, but state regulatory filings in Texas, Massachusetts, and Vermont later confirmed just over 369,200 affected individuals, a fraction of the original claim. The gap between attacker claim and confirmed scope has been wide enough, often enough, that treating leak-site numbers as provisional has become standard practice among security reporters covering these cases.
Market Impact: Kodak’s Financial Position When the Breach Hit
The breach landed at a moment when Kodak (NYSE: KODK) was in the middle of an unusual run of financial improvement. The company had posted four consecutive quarters of year-over-year revenue growth heading into mid-2026, according to its own earnings disclosures. Full-year 2025 revenue came in at $1.069 billion, up $267 million, up 7% year-over-year, with gross margin expanding from 19% to 22%. That momentum carried into 2026: Q1 revenue rose 7% to $265 million, and Q2 2026 revenue, reported August 5, climbed 18% year-over-year to $311 million, according to Kodak’s own press release.
That said, the recovery hasn’t been without friction. Kodak’s Q1 2026 GAAP net loss widened to $16 million from $7 million a year earlier, and the stock dropped roughly 2.48% in after-hours trading following that report. No source reviewed for this article ties a specific stock move directly to the June 2026 breach disclosure itself, and Kodak has not indicated the incident affected guidance. The company’s public breach statement, emphasizing “limited” and “contained,” reads consistently with a management team trying to keep a data-security story from bleeding into a financial-recovery story investors were otherwise reacting well to.
| Quarter | Revenue | YoY Change | Note |
|---|---|---|---|
| Q2 2026 | $311 million | +18% | Fourth straight quarter of YoY growth |
| Q1 2026 | $265 million | +7% | GAAP net loss widened to $16M, shares fell ~2.48% after hours |
| Q4 2025 | $290 million | +9% | Reported March 13, 2026 |
| Full-year 2025 | $1.069 billion | +2% | Gross margin expanded from 19% to 22% |
Source: Kodak quarterly press releases and SEC-linked filings, as compiled through August 2026.
Competitive Comparison: How Kodak Stacks Up Against 2026’s Biggest ShinyHunters Claims
Measured purely by the size of the attacker’s claim, Kodak is one of the smaller entries on ShinyHunters’ 2026 list. The group’s largest 2026 operation targeted Instructure’s Canvas learning platform in late April, with a claimed 3.65 terabytes of data covering roughly 275 million users across nearly 9,000 institutions, reported by TechCrunch. A separate campaign exploiting an Oracle PeopleSoft zero-day compromised more than 100 organizations across roughly 300 vulnerable instances, a claim The Register reported was corroborated by Google’s own threat intelligence team, not just taken at the attacker’s word.
Tech-insider.org has covered two other 2026 ShinyHunters cases directly: the Match Group breach, where the group claimed more than 10 million records from Hinge, Match.com, and OkCupid, and the One Medical breach, where the claim reached 8.8TB of data. Set against that field, Kodak’s 2.2 million records is a mid-sized claim, larger than some of the group’s smaller listings but far below its headline-grabbing operations against education and healthcare targets.
| Organization | Date Listed (2026) | Claimed Scope | Sector | Confirmation Status |
|---|---|---|---|---|
| Instructure (Canvas) | Late April | 3.65TB / ~275M records, ~8,800 institutions | Education technology | Breach confirmed, scope not fully verified |
| Oracle PeopleSoft campaign | June 11 | 100+ organizations, ~300 instances | Cross-sector (zero-day) | Corroborated by Google Threat Intelligence |
| Madison Square Garden | ~July 20 | 26M+ records claimed | Entertainment/venues | Attacker claim, unconfirmed |
| Match Group | January 27 | 10M+ records claimed | Dating platforms | Company says “limited amount” accessed |
| Medtronic | April 18 | 9M claimed / 369,200+ confirmed | Medical devices | Confirmed via state regulator filings |
| Eastman Kodak | June 15 | 2.2M records claimed | Imaging/advanced materials | Company confirms “limited” access, disputes scope |
Source: Company statements and press coverage compiled from BleepingComputer, TechCrunch, The Register, Paubox, and SQ Magazine, current as of August 2026.
Historical Context: From Snowflake Credential Theft to Zero-Day Exploitation
ShinyHunters’ 2026 spree didn’t appear out of nowhere. The group’s tactics trace back to a wave of mass credential-stuffing attacks against Snowflake customer accounts that began in 2024, a campaign that eventually touched more than 165 organizations and exposed hundreds of millions of records at companies including Ticketmaster, AT&T, and Santander, as tech-insider.org detailed in its coverage of the Rockstar Games Snowflake breach. That campaign relied on stolen credentials against a single cloud data platform. Two years later, the group’s methods have diversified considerably: SaaS misconfigurations, a Salesforce-linked social-engineering campaign, and, in the Oracle PeopleSoft case, an actual zero-day vulnerability rather than stolen logins.
That progression matters for how defenders should read the Kodak case. A group that started by abusing weak credential hygiene at scale has since shown it can find and exploit unpatched enterprise software directly. The leak-site business model, publish a victim, set a deadline, threaten reputational damage, hasn’t changed. The technical means of getting in keeps expanding.
Inside ShinyHunters’ Toolkit: Credentials, Zero-Days, and Social Engineering
Kodak hasn’t disclosed the specific entry point the attackers used, but the pattern across ShinyHunters’ 2026 caseload points to three recurring techniques rather than a single signature move. The first is straightforward credential abuse, the same approach that powered the group’s 2024 Snowflake campaign. The second is direct exploitation of unpatched enterprise software, demonstrated most clearly in the Oracle PeopleSoft zero-day that hit more than 100 organizations in June 2026. The third, and increasingly common, is social engineering aimed at help desks and support staff to trick them into resetting credentials or granting access, a technique tied to the group’s Salesforce-linked campaigns this year.
That third technique also shows up in a case tech-insider.org has already covered from a different angle: the EY vendor breach, which exposed client tax documents through a third-party supply-chain compromise. Security outlet Cyberpress reported in late July 2026 that ShinyHunters claimed responsibility for that incident as well, which means at least two of the breaches in this article’s related-coverage list, EY and Kodak, trace back to the same group operating through different entry points within weeks of each other.
The Extortion Economy by the Numbers
Kodak’s case is part of a broader shift researchers have been tracking through 2026: extortion built entirely on data theft, without a traditional ransomware encryption payload at all. Kory Daniels, Chief Security Officer, described the trend bluntly in a discussion of IBM’s 2026 Cost of a Data Breach Report: “We’re seeing that ransomware in fact got worse. It went from 34% up to 39% of data breaches resulting here. So we’re moving in the wrong direction and attackers are shifting to higher impact pressure tactics where they start not just taking your data but they’re really targeting and trying to get you to pay through extortion. They’re targeting your brand reputation.”
Kaspersky’s threat intelligence team reached a similar conclusion in its State of Ransomware 2026 research, writing that “as ransom payments drop, some groups implement encryptionless extortion attacks.” Broadcom’s security research division described the same shift in its own 2026 ransomware report, noting that “these attacks rely on only data theft as a lever for extortion.” Google Cloud’s security team framed it as one of the year’s defining threats in its 2026 Cybersecurity Forecast, describing “modern extortion” built around ransomware and data theft that increasingly bypasses multi-factor authentication rather than confronting it head-on. ShinyHunters is arguably the most visible practitioner of exactly this model: no encrypted files, no ransomware binary, just a leak site, a countdown, and a bet that public pressure closes the deal faster than a court order ever could.
What Kodak Customers and Employees Should Do Now
Kodak has not published a dedicated breach-notification page or confirmed which individuals are affected, which limits what current or former customers and employees can verify directly. Security practitioners generally recommend a standard set of precautions whenever an organization you have a relationship with appears on a leak site, confirmed or not:
- Watch for a formal notification letter or email from Kodak, and verify its authenticity directly through Kodak’s official site rather than clicking embedded links.
- Enable multi-factor authentication on any Kodak-linked account, and on any other account reusing the same password.
- Monitor credit reports and consider a credit freeze if internal corporate data (which can include vendor or payroll records) is confirmed to be part of the exposure.
- Treat unsolicited calls or emails referencing Kodak account details with suspicion, since leaked PII is frequently used to make follow-on phishing attempts more convincing.
- For enterprise customers or partners, ask Kodak directly whether any shared vendor data was part of the “internal corporate data” the attackers described.
Predictions: Where the ShinyHunters Campaign Goes From Here
A few trends look likely to continue through the rest of 2026, based on the pattern established across the group’s confirmed cases so far.
- More publicly traded and consumer-facing companies will appear on the leak site. The group’s targeting has moved from mid-sized SaaS vendors toward household-name brands, and that trajectory shows no sign of reversing.
- The gap between claimed and confirmed record counts will stay wide. Medtronic’s drop from a 9 million claim to a 369,200 confirmed count is likely to repeat, since attacker figures are rarely audited before they’re reported.
- Zero-day exploitation will keep displacing credential theft as the group’s primary entry method. The shift from Snowflake credential stuffing in 2024 to an Oracle PeopleSoft zero-day in 2026 suggests growing technical capability, not just opportunism.
- Expect additional federal advisories. With the cumulative victim count climbing past 130 by some counts, the May 2026 FBI PSA focused on education may be followed by a broader advisory covering other sectors, including manufacturing and imaging companies like Kodak.
- “Contained and limited” statements will keep outnumbering confirmed mass leaks. Several 2026 victims, Kodak included, have avoided a documented full data dump after their deadlines passed, suggesting either quiet payments, prolonged negotiations, or leak-site claims that outpaced what the group could actually deliver.
None of these are certainties, and ShinyHunters’ own history shows it can shift tactics quickly. But the direction of travel, more targets, bigger names, less reliance on stolen passwords, is consistent across every case documented so far in 2026.
Related Coverage
- One Medical Breach: ShinyHunters Claim 8.8TB Stolen [2026]
- Match Group Breach: ShinyHunters Claim 10M Records [2026]
- Rockstar Games Snowflake Breach: Inside ShinyHunters’ Anodot Hack
- Conduent Data Breach: 62.2M Hit, 3rd-Largest Ever [2026]
- EY Vendor Breach: Tax Data Exposed, 81-Day Silence [2026]
- 24 Billion Credentials Leaked in Record Data Dump [2026]
- Suno Breach Exposes 55.3M Accounts, 8 Months Later [2026]
Frequently Asked Questions
What did ShinyHunters claim about the Eastman Kodak breach?
ShinyHunters listed Kodak on its dark-web leak site on June 15, 2026, claiming to hold more than 2.2 million records containing customer PII and internal corporate data. The group set a June 18, 2026 deadline for Kodak to respond before it would publish the data.
Did Kodak confirm the breach?
Kodak confirmed to BleepingComputer on June 18, 2026 that it was investigating unauthorized access to a limited amount of company data. It described the incident as contained and said it did not threaten systems or operations, but it did not confirm ShinyHunters’ 2.2 million record figure.
Who is ShinyHunters?
ShinyHunters is a financially motivated extortion group active since 2020. According to security vendor DoControl, it has breached more than 400 organizations across retail, technology, finance, aviation, and automotive sectors. In 2026 alone, breach trackers have logged anywhere from 86 to over 130 victims on its leak site.
Is ShinyHunters the same group as Scattered Spider or Lapsus$?
Public reporting connects ShinyHunters to overlapping tradecraft and, at times, shared infrastructure with other social-engineering-focused extortion crews, but no primary-source law enforcement statement formally merges ShinyHunters with Scattered Spider or Lapsus$ into a single named organization. Treat “Scattered Lapsus Hunters” as a media shorthand rather than an official designation.
What happened when the ShinyHunters deadline for Kodak passed?
As of this writing, no outlet has documented a confirmed mass publication of Kodak’s data following the June 18, 2026 deadline. Kodak had already acknowledged the incident by that date, and the situation is described in available reporting as contained.
Has the FBI issued any warning about ShinyHunters?
Yes. The FBI’s Internet Crime Complaint Center issued PSA IC3-PSA-2026-0515 on May 15, 2026, warning specifically about ShinyHunters activity targeting learning institutions. No 2026 arrests of ShinyHunters members had been publicly confirmed as of the Kodak listing.
How does the Kodak breach compare to other 2026 ShinyHunters victims?
Kodak’s claimed 2.2 million records is a mid-sized claim relative to the group’s 2026 campaign. It is far smaller than the claimed 275 million records tied to the Instructure/Canvas breach or the 100+ organizations hit through the Oracle PeopleSoft zero-day, but larger than some of the smaller listings on the group’s leak site.
What should companies do to avoid becoming ShinyHunters’ next target?
Security researchers point to the same fundamentals across every 2026 case: patch internet-facing enterprise software quickly, especially SaaS and ERP platforms like PeopleSoft, enforce multi-factor authentication that resists bypass techniques, audit third-party and vendor data access, and build an incident-response and public-communications plan before a leak-site deadline forces one into existence under pressure.


