Kingston Technology
They make the drives other people's data sits on. The interesting exposure is not their customers' data — it is the list of which customers bought protection.
What happened?
Kingston Technology was listed by the Everest ransomware group on August 21, 2026. The listing has not been independently verified, the company has not publicly confirmed an incident, and no data types have been disclosed as of this writing.
Kingston is one of the world's largest manufacturers of memory products, including encrypted USB drives and self-encrypting solid state drives sold into regulated industries.
What data was actually inside?
Not yet disclosed.
Two categories are worth considering, both labeled as inference from the business model. The first is commercial: purchase orders, distributor relationships, and account records describing which organisations bought which products in what quantity. The second is engineering: firmware, key management design, provisioning processes, and certification documentation for products whose security properties are the entire value proposition.
Who gets hurt and how?
The commercial records point at the customers rather than at Kingston. Organisations buy hardware-encrypted storage for a specific reason: they handle data they are required to protect. A purchasing record for encrypted drives is therefore a statement about the buyer — that this defence contractor, this hospital system, or this financial institution has data worth encrypting at rest on removable media, and roughly how much of it.
That does not decrypt anything. It tells an attacker where to look, and it is a category of harm that lands entirely on third parties who were never part of the incident.
Engineering material, if exposed, would matter to every organisation that trusts the product. Questions about firmware or key management provisioning get asked by customers and certification bodies, and they are hard to answer reassuringly.
What did they think they were doing right?
While not publicly confirmed for Kingston, manufacturers selling security-certified products operate under certification regimes that impose genuine engineering rigour on the product itself — design review, key management validation, and independent testing.
Product security and corporate security are separate disciplines with separate owners, and certification covers only the first. A drive can be flawlessly engineered while the enterprise resource planning system holding every purchase order for those drives sits on the corporate network with ordinary protections, because it is understood as a business system rather than as a repository of customer security information.
What did they not know about their own data?
The general lesson here is worth extracting from the specific case. Most organisations classify data by what it says about the people in it. Very few classify data by what it says about their customers' security posture.
Security vendors, penetration testing firms, managed service providers, insurers writing cyber policies, and hardware manufacturers in this category all hold records describing which organisations have which defences, which gaps were found, and what was purchased to close them. None of that is personal data. All of it is operationally useful to an attacker, and almost none of it appears on a data inventory.
Two categories of sensitive material, and only one of them appears on a breach notification checklist.
If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?
What does attribution look like the morning after?
If only commercial and engineering data is involved, personal data notification obligations may be minimal — contact details of purchasing staff would engage GDPR for EU customers, but the bulk of the exposure would sit outside privacy law entirely.
The obligations that bite are contractual and reputational. Enterprise and government customers will invoke notification clauses and ask a specific question: was our purchasing relationship disclosed. Certification bodies will ask whether product security material was affected. Defence and government purchasers may trigger their own supply chain review processes. None of that is governed by a statutory deadline, and all of it requires knowing exactly what was in the affected systems.
What would have changed the outcome?
Classifying the records that describe customers' security posture as sensitive data — because to an attacker they are a target list, whatever the statute says.
Ask which of your records would help someone attack your customers. For most organisations the honest answer is none, and the question is quickly closed. For security vendors, service providers, insurers, and manufacturers of protective products, the answer is a substantial share of the commercial estate — inventoried nowhere, because no privacy regulator has ever asked about it. See also our analysis of the ShinyHunters August listings, which included a security operations provider.
Kingston Technology found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.