Back to Exposure Report
Technology / Imaging June 18, 2026 United States

Kodak

ShinyHunters claims 2.2 million customer records from the 135-year-old imaging company. Kodak confirms unauthorized access but downplays the scope.

Customer PIIInternal corporate dataBusiness records
1

What happened?

ShinyHunters listed Kodak on their leak site on June 15, 2026, claiming to have stolen over 2.2 million records containing customer personally identifiable information and internal corporate data. The group issued a deadline of June 18 for Kodak to respond before publication.

Kodak confirmed on June 18 that "an unauthorized third party illegally gained access to a limited amount of company data." The company declined to confirm the 2.2 million figure or specify what customer data was accessed.

2

What data was actually inside?

ShinyHunters claims customer PII and internal corporate data totaling 2.2 million records. Kodak has not disclosed specific data types. Given Kodak's business—consumer imaging products, commercial printing, and film—customer records likely include names, email addresses, shipping addresses, purchase histories, and potentially payment information.

The "internal corporate data" component suggests employee information, business documents, and operational records may also be in the dump. Kodak's statement that the incident poses "no threat to its systems or operations" is careful corporate language—it says nothing about the threat to affected individuals.

3

Who gets hurt and how?

Kodak customers who purchased cameras, film, printing services, or used Kodak's digital services. Anyone who created an account or made a purchase may have their information exposed. For a 135-year-old brand with generational customer relationships, that's a broad population.

Customer PII enables phishing campaigns, identity theft, and credential stuffing attacks. Email addresses and purchase histories allow for highly targeted social engineering—attackers know what you bought and when. Corporate data exposure affects employees and business partners.

4

What did they think they were doing right?

Kodak's public statement emphasized that "there is no threat to its systems or operations." This framing suggests confidence in their operational security—the business continues to function, production lines are running, corporate systems remain online.

But operational continuity is not the same as data protection. A company can keep running while 2.2 million customer records walk out the door. ShinyHunters doesn't disrupt operations—they take data. The security controls that keep production running aren't the same controls that prevent data exfiltration.

5

What did they not know about their own data?

Kodak described the breach as affecting "a limited amount of company data." ShinyHunters says 2.2 million records. These statements can both be true if Kodak doesn't know what was actually stored versus what should have been retained.

A company with 135 years of history and multiple business pivots—from film to digital to commercial printing to blockchain—accumulates data across generations of systems. Old customer databases, archived e-commerce platforms, legacy CRM records. The breach scope is determined by what actually exists, not what current management believes exists.

If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?

6

What does attribution look like the morning after?

2.2 million records requires reviewing each one to determine whose data was exposed and what notification obligations apply. Kodak sells globally—notification requirements vary by state and country. California, GDPR, state breach notification laws all have different triggers and timelines.

ShinyHunters' public deadline creates pressure. Every day between the claim and confirmation is a day customers don't know they're at risk. The company's careful language—"limited amount"—suggests they're still determining scope. Attribution and notification will take time they may not have.

7

What would have changed the outcome?

Knowing what 2.2 million records actually contained and where they resided—before an attacker mapped the territory first.

When the breach notification says "limited" but the attacker says "millions," somebody doesn't have complete visibility. Data inventory across legacy systems, acquired properties, and decades of business operations would have revealed what was at risk—and enabled data minimization before the breach, not damage assessment after.

Kodak found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.