SecurityAugust 30, 20268 min read

What to Do After the Kodak Data Breach (2026)

PT

By PrivacyOn Team

Privacy Research & Removal Operations

SharePostFacebookEmail
What to Do After the Kodak Data Breach (2026)

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

Kodak (Eastman Kodak Company) confirmed a June 2026 data breach after the ShinyHunters extortion group listed the company on its dark-web leak site and claimed to have stolen more than 2.2 million records containing customer personally identifiable information (PII) and internal corporate data. Kodak says the incident was limited in scope and did not disrupt operations, but it has not disclosed how attackers gained access or issued individual notifications. If you have ever purchased from Kodak, held a Kodak business account, or worked with the company, assume your name, contact info, and account details may be circulating — move 2FA off SMS, freeze your credit, and remove your personal data from broker sites so attackers cannot build a full profile on you.

What Happened in the Kodak Data Breach?

On June 15, 2026, the ShinyHunters extortion group added kodak.com to its dark-web data leak site. The listing described "over 2.2 million records containing customer PII and other internal corporate data" and set a hard deadline: Kodak had until June 18, 2026 to open ransom negotiations or the group would publish the stolen data.

Kodak subsequently confirmed unauthorized access to its systems, telling multiple security outlets that the incident was "limited in scope, contained, and did not pose a threat to its systems or operations." The company has not, as of publication, publicly disclosed how the attackers gained access, confirmed the record count, or explained why individual notifications have not gone out at scale.

The Kodak intrusion fits a pattern security researchers have tracked throughout 2026: ShinyHunters targeting enterprise platforms and third-party integrations (Salesforce, Oracle PeopleSoft, and similar systems) at Fortune 500 companies, then extorting them under short public deadlines.

What Data Was Exposed?

Kodak has not itself confirmed a specific list of exposed fields. Based on ShinyHunters' public claims and the shape of similar 2026 breaches by the same group, the stolen dataset likely includes:

  • Customer names and account identifiers
  • Email addresses (personal and business)
  • Phone numbers
  • Physical and shipping addresses
  • Order and account histories
  • Internal corporate documents (contracts, spreadsheets, internal communications)
  • Possibly partial payment metadata (last-4 of card, order totals) — ShinyHunters typically does not obtain full card numbers, but transaction records were named in comparable 2026 breaches

The 2.2M figure is not yet independently verified

The 2.2 million record count comes from ShinyHunters' own leak-site listing. Kodak has neither confirmed nor denied it. Until the company or a third party publishes an authoritative figure, treat 2.2M as an allegation — but treat the leak itself as real: Kodak has confirmed unauthorized access, and ShinyHunters' past claims have generally matched what later appeared in the dumps.

Are You Affected?

Assume you may be affected if you have:

  • Purchased Kodak consumer products (cameras, film, printers, ink, storage media) through Kodak's direct-to-consumer channels
  • Held a business or dealer account with Kodak (commercial printing, packaging, motion picture film)
  • Registered a Kodak product warranty or created an account on kodak.com
  • Subscribed to Kodak newsletters, promotional emails, or loyalty programs
  • Been a Kodak employee, contractor, or vendor whose contact info sat in an enterprise system

Because Kodak has not sent individual notifications, absence of a letter does not mean you are safe. Check HaveIBeenPwned periodically for your email to appear in a "Kodak" listing once the dataset is fully indexed.

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Immediate Steps to Take

Step 1: Change Your Kodak Password and Any Reused Passwords

Log in to kodak.com (or the specific Kodak product portal you use) and change your password. If you reused that password anywhere else — email, bank, Amazon, work SSO — change those too, and this time use a unique password per site. A password manager makes this manageable in about 15 minutes.

Step 2: Move 2FA off SMS

Because phone numbers were almost certainly in the leaked dataset, SIM-swap risk is elevated. Move two-factor authentication from SMS to an authenticator app (Google Authenticator, Authy, 1Password) or a hardware security key (YubiKey) on your email, bank, and any other account that offers it. Call your mobile carrier and add a port-out PIN or number-lock feature.

Step 3: Freeze Your Credit at All Three Bureaus

A credit freeze is free, reversible, and blocks new-account fraud — the single most damaging outcome when a name, address, and date of birth leak together. Freeze at all three bureaus:

You can thaw a freeze in minutes when you actually need new credit.

Step 4: Expect Targeted Phishing and Vishing

ShinyHunters typically sells or leaks stolen data to secondary actors within weeks. Expect emails and calls that reference your real Kodak orders, product registrations, or account details in the next 30-90 days. Rules for the household:

  • No legitimate Kodak email will ever ask you to "verify your account" via a link — type kodak.com manually
  • Any inbound call claiming to be Kodak support gets hung up and called back through the number on the official Kodak website
  • Any "data breach settlement" email asking for your bank info to "send you compensation" is a scam — legitimate settlements go through mailed notices and named administrators

Step 5: Monitor Your Bank and Card Statements for 90 Days

Even without full card numbers in the leak, criminals who buy the Kodak dump will cross-reference emails against other stolen data (2024's National Public Data leak, the ongoing Salesforce breach wave, and older dumps) to build complete identity packages. Turn on transaction alerts for every card and account, and dispute any charge you do not recognize within the 60-day federal window.

Cut the Trail: Remove Your Data From Broker Sites

The Kodak leak on its own is only part of your exposure. Attackers pair a breach dataset with data-broker profiles — Spokeo, BeenVerified, Whitepages, and 100+ similar sites — to build a complete picture: your home address, relatives, current phone, past addresses, and employment. Combining a real breach with a real broker profile is what turns a generic phishing email into a hyper-targeted attack that references your spouse, your street, and your last purchase.

Removing your data from those brokers breaks the chain. When an attacker looks you up after the Kodak leak and finds nothing tying your name to a current address, family members, or phone number, most give up and move on to easier targets.

PrivacyOn shrinks your public footprint fast

PrivacyOn removes your personal information from 100+ major data broker sites, adds 24/7 dark web monitoring for your email addresses, and covers up to 5 family members from $8.33/month. Start with a free scan to see exactly which brokers are exposing your address, relatives, and phone number — the same data attackers will try to cross-reference against the Kodak dump the moment it circulates.

Longer-Term Protection

  • Use email aliases for new signups (iCloud Hide My Email, Firefox Relay, DuckDuckGo Email Protection) so the next Kodak-style leak burns an alias, not your primary inbox
  • Add dark-web monitoring for every email address you use so you get an alert when your data appears in a new dump
  • Enable phishing-resistant MFA (hardware keys) on your email, financial accounts, and any other high-value login
  • Set a fraud alert at all three credit bureaus as a low-effort supplement to a freeze — alerts force lenders to verify identity before opening new credit in your name
  • Report identity theft at IdentityTheft.gov if you see account takeovers or new accounts you did not open
  • Watch for a class action — breaches of this size typically produce plaintiff-firm investigations within weeks; save any Kodak correspondence in case you are eligible to join

Frequently Asked Questions

Is the Kodak 2026 data breach confirmed?

Yes. Eastman Kodak Company publicly confirmed unauthorized access after ShinyHunters listed the company on its dark-web leak site on June 15, 2026 and claimed to have stolen more than 2.2 million records. Kodak has described the incident as limited in scope and contained, but has not yet publicly confirmed the record count or the exact data types involved.

How many people were affected by the Kodak breach?

ShinyHunters claims over 2.2 million records containing customer PII and internal corporate data. Kodak has not confirmed a specific number. Until an independent count is published, treat 2.2 million as the working estimate and assume you may be affected if you have ever purchased from Kodak, registered a product, or held any Kodak account.

What information was stolen in the Kodak breach?

Based on ShinyHunters' claims and the pattern of comparable 2026 breaches by the same group, the exposed data likely includes customer names, email addresses, phone numbers, physical addresses, order histories, and internal corporate documents. Kodak has not published an official list of exposed fields. Assume full contact info exposure and act accordingly.

Did Kodak lose credit card or Social Security numbers?

Kodak has not confirmed either way, and ShinyHunters typically does not obtain full payment card numbers in these enterprise breaches. However, order records and partial payment metadata (last-4 of card, order totals, shipping addresses) are common in these dumps, and criminals combine them with older stolen data to attempt fraud. A credit freeze remains the safest response regardless of whether SSNs were in this specific dataset.

How did the Kodak data breach happen?

Kodak has not publicly disclosed the attack vector. Throughout 2026, ShinyHunters has repeatedly compromised Fortune 500 companies by exploiting enterprise platforms and third-party integrations — including Salesforce (via vishing-based account takeover) and Oracle PeopleSoft (via the CVE-2026-35273 zero-day). Kodak's intrusion fits that broader pattern, though the specific entry point has not been confirmed.

Should I get identity theft protection after the Kodak breach?

The single most effective step is a free credit freeze at all three bureaus — that alone blocks the highest-impact fraud. Beyond that, the best value is removing your data from the broker sites attackers use to enrich stolen breach data. PrivacyOn is our top pick: $8.33/month covers 100+ data brokers, dark-web monitoring, and up to 5 family members. That combination shrinks your exposed footprint faster than a pure credit-monitoring product and costs a fraction of what LifeLock or Aura charge.

Is there a class action lawsuit for the Kodak data breach?

Plaintiffs' firms typically announce investigations within weeks of a confirmed breach of this size. As of publication, no class action has been formally certified, but investigations are likely under way. Save any Kodak correspondence, screenshot any breach-related emails you receive, and check reputable class-action tracker sites periodically if you want to participate.

What should I do if I never bought anything from Kodak?

You are unlikely to be affected as a consumer. However, if you have ever worked at, contracted with, or supplied Kodak — or if your employer used Kodak enterprise services — your business contact info may still be in the leaked dataset. The same defensive steps (2FA hardening, credit freeze, broker removal) are cheap and cumulative regardless of which breach they respond to.

SharePostFacebookEmail
PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families