On June 15, 2026, the ransomware group ShinyHunters listed kodak.com on its leak site and gave the company until 18 June 2026 to pay or face the public release of more than 2.2 million records containing customer PII and internal corporate data.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch kodak.com
Get alerted the next time kodak.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about kodak.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes an initial ransomware attack that resulted in the exfiltration of internal files. The group posted a final warning on its leak site, stating that failure to pay would lead to the data being leaked along with additional digital consequences. The deadline was set for 18 June 2026, with the post updated on 16 June 2026. Public reporting indicates the compromised material includes customer personally identifiable information, though the exact number of uniquely affected individuals remains unknown. The incident follows the group’s typical pattern of using a leak site to pressure victims after data has already been stolen.
Why This Matters for You and Your Family
If your personal information was among the 2.2 million records allegedly taken from Kodak, it can be used to open accounts in your name, file fraudulent tax returns, or impersonate you in phishing attacks. For families this often means children’s data is exposed alongside parents’, creating long-term risks that stretch across years. A single breach like this rarely stays isolated; the exposed details tend to appear on multiple underground markets, increasing the chance that someone in your household will face identity theft or targeted scams. Even when the victim count is listed as unknown, the scale of 2.2 million records suggests many ordinary customers are now at higher risk.
The Doxxing and Identity-Chain Implications
Stolen customer PII frequently serves as the first link in a doxxing chain. An email address or phone number allegedly taken from Kodak can be correlated with gaming usernames, social-media handles, and family addresses. Once attackers map these connections, they can hijack accounts, publish personal details, or harass family members. Credential leaks of this type commonly cascade into gaming account takeovers, especially for children who reuse passwords or security questions derived from family data. The result is not a single incident but a widening web of exposure that can surface months or years later.