Skip to content
Data breachUnknown

American Tower data leak exposes cell-tower gate codes (ShinyHunters extortion)

Extortion group ShinyHunters claimed to have stolen more than 5.2 million records from telecom infrastructure owner American Tower and published data including contact details for over 200,000 people as well as GPS locations and plaintext gate access codes for U.S. cell-tower compounds.

Victim
American Tower Corporation
users
216.6K

On 12 June 2026, the extortion collective ShinyHunters claimed it had breached American Tower Corporation, one of the world's largest owners of wireless communications towers, and stolen more than 5.2 million records. The listing was part of the group's wider "pay-or-leak" campaign that month, which also hit insurers, healthcare providers and entertainment companies.

When the deadline passed, ShinyHunters published data that breach-notification service Have I Been Pwned added on 26 June 2026: 216,601 unique email addresses belonging to employees, contractors, customers and sales leads, together with names, job titles, phone numbers and physical addresses.

Physical-security exposure

Beyond personal data, the leaked material reportedly included GPS coordinates of tower sites, tower asset records, internal documents and plaintext physical access codes for the gates of U.S. cell-tower compounds. The group also claimed the files referenced other organizations, including T-Mobile, Verizon and the Department of Homeland Security. Unlike a password, a gate code cannot be reset remotely; changing it requires a technician visit to each site.

American Tower had not publicly confirmed or denied the breach as of later reporting, and the group's 5.2 million record figure was not independently verified.

Why it matters

Cell towers are shared infrastructure for every major U.S. carrier, so a leak combining site locations with working access codes turns a data breach into a physical-security risk for telecom networks, potentially enabling sabotage or equipment theft. The incident shows how the 2026 wave of SaaS and CRM data-theft campaigns can expose operational details of critical infrastructure, not just customer contact lists.

Timeline

  1. ShinyHunters claims responsibility for a breach of American Tower, alleging more than 5.2 million stolen records.

  2. Have I Been Pwned adds the published dataset, counting 216,601 unique email addresses.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/Breach/AmericanTower
  2. gcn.comhttps://gcn.com/shinyhunters-publishes-american-tower-cell-tower/21549

Related incidents