SecuritySeptember 10, 20268 min read

What to Do After the American Tower Data Breach (2026)

PT

By PrivacyOn Team

Privacy Research & Removal Operations

SharePostFacebookEmail
What to Do After the American Tower Data Breach (2026)

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

American Tower was named in the 2026 ShinyHunters extortion wave, and the attackers published a dataset containing roughly 574,000 unique email addresses along with names, phone numbers, physical addresses, and geographic data. Most affected people are cell-tower landowners, lessees, and business contacts — not consumers. Expect targeted impersonation, not credit fraud.

What Happened in the American Tower Data Breach?

American Tower Corporation is one of the largest owners and operators of wireless communications infrastructure in the United States — the company that owns the towers your carrier's antennas sit on and leases the land underneath them. In June 2026 it was named on the extortion portal of ShinyHunters, the group behind the year's long-running campaign against enterprise Salesforce environments.

The pattern is consistent across that campaign: attackers phone an employee, impersonate internal IT support, and walk them into granting access to the company's CRM. ShinyHunters gave American Tower a deadline of June 15, 2026 to make contact, then published data when no payment followed.

Two Very Different Numbers

ShinyHunters claimed over 5.2 million records in total. The dataset actually published and indexed by breach-notification services contains about 574,000 unique email addresses. Attacker claims routinely inflate row counts by counting every database row, including duplicates and non-personal asset records. Treat 574,000 as the number of real people confirmed exposed.

What Data Was Exposed?

The published personal dataset includes, for roughly 574,000 individuals:

  • Email addresses
  • Full names
  • Phone numbers
  • Physical addresses
  • Geographic data tied to those records

Beyond individual PII, the attackers claimed the haul also contained tower asset records — GPS coordinates and, more seriously, plaintext physical access and gate codes for cell tower compounds across the United States — plus records tied to tenant organizations including major carriers and government agencies. American Tower has not publicly confirmed the scope of those claims, and no broad public statement detailing consumer notification has been issued as of this writing.

What is not reported in the published dataset: Social Security numbers, full payment card numbers, bank account details, or account passwords.

Who Is Actually Affected?

This is not a consumer breach in the way a retailer or bank breach is. If your email is in this dataset, you are most likely one of the following:

  • A landowner who leases ground to American Tower for a cell site
  • A tenant or carrier contact whose company leases space on a tower
  • A vendor, contractor, or field technician who works on tower sites
  • An American Tower employee or business counterparty

If you are simply a mobile phone customer of a carrier that rents tower space, you are almost certainly not in this dataset — American Tower does not hold your subscriber account.

Why This Breach Is Unusually Targeted

Ordinary breach data is used at scale: dump the list, spam it, see who bites. This dataset is different because it identifies people by their role. An attacker knows you are the landowner on a specific parcel, or the site contact for a specific carrier, and holds your name, phone, address, and location data to prove it.

That enables very credible spear-phishing: a call about your lease payment, an emailed "amended lease agreement" carrying malware, a request to update the bank account your rent check goes to. Lease-payment redirection fraud is a real and expensive attack against exactly this population.

Step 1: Verify Anyone Claiming to Be American Tower

Assume for the foreseeable future that any inbound call, email, or letter about your tower lease could be from someone holding the leaked file. They will know your name, your address, and your site. That is no longer proof of anything. Hang up or set the email aside, then contact American Tower through the phone number on your existing lease paperwork or the company's official website.

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Step 2: Lock Down Payment Change Requests

If you receive rent or lease payments, treat any request to change the receiving bank account as fraudulent by default. Confirm it by voice with a known contact using a number you already had — never one supplied in the request. If you administer payments for an organization, require dual approval on banking changes. This single control defeats the most profitable version of this attack.

Step 3: Move Two-Factor Authentication Off SMS

Phone numbers leaked. That makes SIM-swap and SMS-interception attacks a realistic next step, particularly against people whose email addresses are also known. Switch your important accounts — email first, then banking and any business portals — to an authenticator app or hardware key. Then call your mobile carrier and add a port-out PIN to your line.

Step 4: Watch for Malicious Attachments Framed as Lease Documents

Expect PDFs and Office files named like real lease amendments, site access forms, or insurance certificates. Open nothing that arrives unexpectedly, even when the sender name and site details are correct. Verify by voice first; if the document is genuine, the sender will not mind.

Step 5: Freeze Your Credit Anyway

No Social Security numbers were reported in this leak, so new-account fraud is not the primary risk here. A freeze at Equifax, Experian, and TransUnion is still free and still worth 15 minutes — breach data circulates, gets combined with older dumps, and resurfaces years later. Freezing costs nothing and removes the worst-case outcome from the table.

Step 6: Shrink Your Public Footprint

The leaked file gives an attacker your name, phone, address, and role. Data broker and people-search sites supply the rest: your age, relatives, previous addresses, property records, and additional phone numbers. Combined, those turn a plausible pretext into a convincing one — and landowners are easy to find in public property records to begin with.

PrivacyOn removes your personal information from 100+ data broker and people-search sites, monitors continuously for re-listings, and scans the dark web for your details, starting at $8.33/month with family plans covering up to 5 people. Taking the broker profile offline is the one step that reduces your exposure rather than just watching it. Start with a free PrivacyOn scan to see what is publicly available about you today.

Quick Checklist

Call back on a known number before trusting any American Tower contact. Refuse unverified banking-change requests. Move 2FA to an authenticator app and add a carrier port-out PIN. Do not open unexpected lease documents. Freeze all three credit bureaus. Remove your profile from data broker sites.

Frequently Asked Questions

Was I affected by the American Tower data breach?

You are most likely affected if you are a tower landowner, a carrier or tenant site contact, a vendor or contractor, or an American Tower employee. The published dataset holds roughly 574,000 unique email addresses of business contacts and landowners. Regular mobile phone subscribers are generally not included, because American Tower does not hold carrier subscriber records.

Was my Social Security number exposed?

Not according to the published dataset, which contains names, email addresses, phone numbers, physical addresses, and geographic data. No Social Security numbers, full card numbers, or passwords have been reported. The realistic threat is targeted impersonation and payment-redirection fraud rather than new-account identity theft.

Did hackers really get cell tower gate codes?

ShinyHunters claimed the stolen data included tower asset records with GPS coordinates and plaintext physical access codes for tower compounds. American Tower has not publicly confirmed that claim. If you are responsible for site access at any location, treat existing codes as potentially compromised and rotate them.

Has American Tower notified affected people?

As of this writing there is no broad public statement from American Tower detailing a consumer notification program. If you have a lease or vendor relationship, contact the company directly through the number on your paperwork rather than waiting, and be skeptical of any "breach notification" email that arrives with a link.

What should landowners do first?

Protect the money. Refuse any request to change the bank account your lease payments go to unless you confirm it by voice with a contact and number you already had on file. That is the highest-value attack available to anyone holding this data, and a single verification call defeats it.

How do I reduce the risk of targeted scams after a breach like this?

Cut the amount of public information an attacker can combine with the leak. People-search sites publish your age, relatives, prior addresses, and extra phone numbers for free, and property records make landowners especially easy to profile. PrivacyOn removes your details from 100+ of those broker sites and keeps them off, which makes a convincing pretext much harder to build.

SharePostFacebookEmail
PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families