Breach taxonomy
Summary
ADT became aware of unauthorized activity on its network and discovered an unauthorized actor had accessed ADT's network using compromised credentials obtained through a third-party business partner. The company shut down the access, notified the third party its systems were compromised, engaged cybersecurity experts, and notified law enforcement. The unauthorized actor exfiltrated certain encrypted internal ADT data associated with employee user accounts. No customer personal information was exfiltrated and no customer security systems were compromised. Containment measures caused some disruption to ADT's information systems. Filed under Item 8.01; company did not assert materiality determination.
Tagging rationale
ThreatUnknown
Filing does not attribute the incident to a specific actor category → UNKNOWN.