Back Techtimes Kodak Confirms Data Breach as ShinyHunters Threatens Leak of 2.2M Records
Eastman Kodak confirmed Wednesday that an unauthorized third party illegally gained access to a portion of its data, as the ShinyHunters extortion group claimed responsibility on its dark web leak site and threatened to publish the stolen files if Kodak fails to make by Thursday, June 18, 2026 — a deadline hours away at publication time.
BleepingComputer first reported the company's confirmation. ShinyHunters claims to have exfiltrated more than 2.2 million records containing customer personally identifiable information and internal corporate data. Kodak — which today operates primarily as a business-to-business manufacturing and technology firm, not a consumer brand — has not verified that figure, and the group has released no proof samples to substantiate it. Because Kodak's customers are corporations and industrial partners rather than retail consumers, the risk from the claimed theft extends beyond phishing: corporate personally identifiable information from a licensing and manufacturing company typically includes purchasing contacts, procurement data, contract details, and business email addresses — exactly the information needed to execute supplier fraud and business email compromise against third parties across Kodak's supply chain.
ShinyHunters listed Kodak on its Tor-hosted extortion portal on June 15, 2026, alongside several other major corporate targets claimed the same day: Sysco Corporation, the U.S. food distribution giant (61 million Salesforce records claimed), and Houston City College in Texas (hundreds of thousands of student records purportedly compromised). The gang's message to Kodak was terse: "Over 2.2 million records with customer PII and other internal data were compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way."
A Kodak spokesperson told BleepingComputer that the company had "recently discovered that an unauthorized third party illegally gained temporary access to a limited amount of company data," that it had engaged external cybersecurity experts to investigate what was accessed and copied, and that it is working with law enforcement. Kodak added that it is "confident there is no threat to our systems or operations" — but did not respond to a follow-up question asking whether its internal network itself had been breached.
The gap between ShinyHunters' 2.2 million record claim and Kodak's "limited amount" characterization is consistent with how the group operates: it routinely withholds proof samples before a deadline, using the threat of publication as leverage rather than committing to evidence up front.
ShinyHunters is a financially motivated extortion group active since 2019, now considered one of the most prolific data-theft operations in history. The group — affiliated with The Com, a loose international cybercrime network that also includes elements of Scattered Spider and former Lapsus$ members — operates under a blunt "pay or leak" model: steal data, set a short deadline, and publish if the target refuses to engage.
Despite multiple law enforcement actions — including the 2022 arrest of French national Sébastien Raoult (sentenced to three years in prison and ordered to pay $5 million in restitution in January 2024) and the coordinated arrest of four additional suspected members in France in June 2025 — ShinyHunters has continued operating without meaningful interruption. The group's decentralized structure makes it resilient to individual arrests: the name is believed to reference Shiny Pokémon, rare color variants that players spend enormous time searching for, and the group's persistence mirrors that obsession.
In 2026 alone, ShinyHunters has claimed responsibility for breaches at Instructure Canvas (affecting students across an estimated 9,000 educational institutions, per ShinyHunters' own count), Charter Communications (42 million records claimed), Oracle PeopleSoft (more than 100 organizations via a critical zero-day vulnerability, CVE-2026-35273, rated 9.8 out of 10 on the Common Vulnerability Scoring System scale), and dozens of other organizations through a campaign exploiting misconfigured Salesforce Experience Cloud instances that the group says has produced more than 1.5 billion stolen records dating back to September 2025.
The group has a documented pattern of following through when extortion demands go unmet. When 7-Eleven did not pay by the April 21, 2026 deadline, ShinyHunters published a 9.4-gigabyte archive of stolen files on April 22 — including Social Security numbers and driver's licenses of franchise applicants — and later listed the dataset for sale at $250,000 on a prominent hacker forum.
Allison Nixon , chief research officer at cybersecurity firm Unit 221B, has publicly urged organizations targeted by ShinyHunters not to pay. "They rely on the intensity of their emotional manipulation to force you to make a snap decision, within 72 hours, to pay the ransom," Nixon told PCMag. "They don't have a convincing argument why you should pay in the first place. Their only answer to you is that they will hurt you. But that's not a rational answer."
The FBI's guidance aligns with that assessment. In a May 2026 advisory issued by its Internet Crime Complaint Center, the bureau warned that ShinyHunters commonly uses harassment strategies — including threatening text messages and calls to victims and their family members, and in some cases swatting — and strongly discouraged victims from paying any extortion demand. Payment funds future attacks, rarely guarantees data deletion, and often invites repeat targeting, the bureau noted.
Instructure, the Canvas developer, took a different path: it paid the group's extortion demand in May 2026, reaching an "agreement" that included a shred log as digital confirmation the stolen data had been destroyed. Security researchers widely criticized the decision, noting that whether ShinyHunters actually destroyed the data — or had already copied it across multiple infrastructure nodes — is unknowable.
Founded in 1880 as Eastman Kodak Company and headquartered in Rochester, New York, Kodak emerged from bankruptcy in 2013 as a primarily business-to-business enterprise. It holds approximately 79,000 patents worldwide and today focuses on commercial digital printing, motion picture and still film, specialty chemicals for pharmaceutical and battery production, and brand licensing.
That B2B profile is central to assessing the breach's potential impact. Corporate personally identifiable information in Kodak's systems is likely to include purchasing contacts, procurement agreements, licensing terms, and business email addresses for industrial clients across multiple sectors. That data provides threat actors with the raw material for highly targeted business email compromise — impersonating vendors, finance teams, or procurement contacts to redirect payments or extract credentials.
Kodak has not disclosed the categories of data it believes were accessed, nor has it confirmed whether the incident triggers mandatory notification requirements under the European Union's General Data Protection Regulation, the California Consumer Privacy Act, or applicable U.S. state breach notification statutes. Under GDPR Article 33, organizations must notify regulators within 72 hours of becoming aware of a breach likely to risk individuals' rights; failure to meet that deadline can result in fines of up to €20 million or four percent of global revenue. All 50 U.S. states maintain their own notification laws with varying deadlines.
The June 18 deadline arrives Thursday. Kodak has not stated publicly whether it has made with the threat actors. Under ShinyHunters' stated model, non-response results in public publication of the alleged 2.2 million records alongside unspecified "annoying (digital) problems" — a phrase the group has used in ultimatums to Rockstar Games, Oracle PeopleSoft victims, and others this year.
Whether Kodak chooses to pay or not, security experts broadly note that payment provides no enforceable guarantee of data deletion and no protection against a second round of extortion by the same or affiliated actors. The FBI advises all victims to report incidents to the bureau rather than negotiating directly with threat groups.
What did ShinyHunters claim to steal from Kodak?
ShinyHunters claims to have stolen more than 2.2 million records containing customer personally identifiable information and internal corporate data. Kodak has confirmed that an unauthorized party accessed "a limited amount" of data but has not verified the scope of ShinyHunters' claim, and the group has not released any proof samples.
Should Kodak pay the ShinyHunters extortion demand?
The FBI strongly discourages paying extortion demands, warning that payment funds future attacks and rarely results in actual data deletion. Cybersecurity firm Unit 221B, whose chief research officer Allison Nixon has studied ShinyHunters extensively, advises organizations to resist the group's pressure tactics and engage law enforcement instead. Payment does not prevent re-extortion by the same actors.
What is the risk to Kodak's customers and business partners?
If the breach is confirmed at the scale ShinyHunters claims, the stolen corporate personally identifiable information could enable targeted phishing campaigns, business email compromise, and supplier fraud directed at organizations across Kodak's supply chain — not just at individuals whose personal data may have been exposed.
What should I do if I am a Kodak customer or partner?
Watch for suspicious emails appearing to come from Kodak contacts, particularly any that request payment changes, credential updates, or urgent financial action. Kodak has not yet issued direct customer notifications; monitor official Kodak communications for guidance on whether your data was affected and whether a formal notification is coming.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
