Supply chain [SC] Supply Chain

ADT Third-Party Breach (October 2024)

2024-10-01 [vendor] Third-party business partner
Primary Source ↗

Incident Details

ADT discloses second breach in 2 months, hacked via stolen credentials. Home and small business security company ADT disclosed it suffered a breach after threat actors gained access to its systems using stolen credentials and exfiltrated employee account data. ADT is a public American company that specializes in security and smart home solutions for residential and small business customers. The firm employs over 14,000 people and has an annual revenue of $4.98 billion. In a Monday evening FORM 8-K filing filed with the SEC, the company says that credentials were stolen from a third-party business partner that allowed threat actors to breach ADT’s systems. Third-party company: Third-party business partner.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Third-party business partner
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2024-10-01 Breach occurred
  2. 2024-10-07 Publicly disclosed