Ransomware victim disclosure
← All victimsAmerican Tower Corporation
Claimed by Shinyhunters · listed 3 days ago
Status timeline
- ListedJun 12, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Telecommunication
- Listed on leak site
- Jun 12, 2026
About the victim
AI dossier — public-source company profileAmerican Tower Corporation is a major U.S. telecommunications infrastructure company that owns and operates cell towers and related assets across the United States, serving major carriers and providing critical connectivity infrastructure.
- Industry
- Telecommunications Infrastructure
Attack summary
Severity: critical — Confirmed exfiltration of 5.2M+ records including PII at scale, government agency data (DHS), physical security data (GPS + access codes for critical telecommunications infrastructure), and data from regulated carriers. Poses direct risk to national security, consumer privacy, and physical infrastructure security.Shinyhunters claims to have exfiltrated over 5.2 million records including customer PII, landowner PII, records from third-party carriers (T-Mobile, Verizon) and U.S. DHS, tower asset data with GPS coordinates and plaintext physical access codes for cell tower compounds, and internal corporate data.
Data the group says was taken
AI dossier — extracted from the leak post- customer PII
- landowner PII
- third-party carrier records (T-Mobile, Verizon, DHS)
- cell tower GPS coordinates
- physical access codes and gate codes
- tower asset records
- internal corporate data
What the group claims
Over 5.2 million records consiting of a significant amount of customer and landowner PII, other records tied to other companies such as T-Mobile, Verizon, and the US DHS, several tower asset records containing GPS data and plaintext physical access/gate codes for cell tower compunds across the United States, thousands of internal corporate data, and a lot more were compromised. We urge you to reach out. This is a final warning to reach out by 15 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 June 2026 | Warning: FINAL WARNING PAY OR LEAK
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

