ADT, Inc. Data Breach Notice (Washington Attorney General)
If you received a notice from ADT, Inc., here’s what the filing says was exposed, and what to do about it.
ADT, Inc. notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on July 28, 2026, and the notice lists name, social security number and full date of birth among the information exposed. The filing puts the incident itself on April 20, 2026.
The April 20, 2026 breach at ADT, Inc. exposed the Social Security numbers and full dates of birth of 5,129 people. That combination does not expire and cannot be replaced. If you were among those notified, the records that identify you for life are now outside the company’s control.
A 99-day gap between incident and notification
The filing states the incident occurred on April 20, 2026. ADT, Inc. submitted the breach notice to the Washington Attorney General on July 28, 2026 — exactly 99 days later. This interval is the single most concrete fact the record provides. Notification timelines vary by state and by when an investigation concludes, so the filing itself does not label the delay as unusual. It simply records both dates and the number of Washington residents affected.
What the exposed information actually enables
Name, Social Security number, and full date of birth together form the core set of details required to open new accounts, request credit, file fraudulent tax returns, or impersonate someone in government systems. A Social Security number paired with a date of birth is the exact combination lenders and credit agencies have used for decades to verify identity. Once that pair leaves a company, the risk does not diminish with time.
No passwords were exposed. The filing lists only the three categories above. This means your ADT account itself was not compromised in a way that allows direct login theft. That is genuine good news and removes one immediate worry.
The lifelong nature of these identifiers
Unlike a credit card or password, a Social Security number cannot be reissued on request. A date of birth never changes. The people whose records were included in this incident therefore carry an elevated risk of identity theft for the rest of their lives. Credit monitoring for a few years is helpful but does not solve the permanent problem these two pieces of information create.
The record does not disclose whether the data was encrypted at rest, how the breach occurred, or how it was discovered. Those uncertainties remain. What is certain is that 5,129 individuals now have their most sensitive government identifiers in unknown hands.
How to determine whether this notice applies to you
ADT is required to notify affected individuals directly, usually by mail. If you have not received a letter, your information was most likely not included. However, anyone who has moved since April 20, 2026 should contact ADT directly to confirm their status. Absence of a letter is usually meaningful, but last-known-address problems are common.
The practical risk today
With your name, SSN, and date of birth an attacker can:
- Apply for credit cards or loans in your name
- File fraudulent tax returns to claim refunds
- Open bank accounts or utility services
- Impersonate you when dealing with government agencies
These are not theoretical future risks. They are the standard uses of this exact data combination once it has been exposed.
What remains under your control
You cannot change the exposed data, but you can reduce what an attacker is able to do with it. The most effective steps focus on early detection and blocking new account fraud rather than trying to hide information that is already public.
Placing a freeze is the strongest single action
A credit freeze prevents new creditors from accessing your credit file. It does not affect existing accounts. Place freezes with Equifax, Experian, and TransUnion now. The process takes minutes per bureau and is free. You will receive PINs or codes required to lift the freeze only when you need to apply for new credit. This single step stops most new-account identity theft that uses stolen SSNs.
Ongoing monitoring beats one-time checks
Place a freeze first, then add active monitoring that alerts you whenever new inquiries or accounts appear. Review your annual credit reports from all three bureaus, but treat them as historical records rather than real-time protection. The combination of a freeze plus alerts gives you the fastest practical warning if someone tries to use your SSN.
Tax fraud requires its own defense
File your taxes as early as possible each year. Consider submitting Form 14039, Identity Theft Affidavit, to the IRS if you have any reason to believe your SSN may be used fraudulently. The IRS now flags returns filed with known compromised SSNs more aggressively than in previous years.
Medical and insurance vigilance
Although medical information itself was not listed in this filing, a date of birth and SSN can be used to create fake health insurance claims. Review Explanation of Benefits statements carefully. Report any unfamiliar claims to your insurer immediately.
The 5,129 people named in this Washington filing now share a permanent risk that did not exist before April 20, 2026. The letter you may have received is the only reliable way to know whether you are one of them. If the letter arrived, the steps above represent the most practical defense available. The data cannot be taken back, but its usefulness to criminals can still be sharply limited.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on ADT, Inc..
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Expect the phone calls to get better. A date of birth is not secret, but it is what call centres use to confirm you are you. Treat any unexpected call that already knows your details as unverified until you call the company back yourself.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
ADT 5.5–10 Million Customer Records Disclosed — April 2026
ADT confirmed unauthorized access to between 5.5 and 10 million customer records in April 2026. Expo…
Victory Personal Care, Inc Listed by Nightspire Ransomware Group
Victory Personal Care, Inc was listed on the Nightspire ransomware leak site. The group claims to ha…
Victory Personal Care, Inc Listed by nightspire Ransomware Group
Data is not available now.…