CHECKLEAKED.CC

Loading

Classic site

FORENSIC ANALYSIS

Fluke Corporation compromised in extortion campaign and third-party application breach

Fluke Corporation was impacted by a July 2026 extortion leak and a separate network breach disclosed in May 2026. Threat group ShinyHunters published over 100GB of data containing corporate contact details and customer support tickets across 821,100 accounts. Fluke also notified 18,517 individuals regarding the earlier network breach that exposed Social Security numbers and disability indicators.

Sources12Publishers12Cited claims23See the sources

What happened

In July 2026, electronic test and measurement equipment manufacturer Fluke Corporation was targeted in an extortion campaign by cybercrime group ShinyHunters[1][7]. After demanding payment, the group published more than 100GB of data allegedly stolen from the company[1][4]. The published corpus largely comprised corporate contact records and internal customer support cases[1][8].

The extortion publication followed a separate security incident disclosed by Fluke earlier in May 2026[3][9]. In that incident, an unauthorized actor maintained access to a limited segment of Fluke's corporate network from August 10, 2025, to October 7, 2025[10][11]. A forensic review completed on May 8, 2026, determined that personal records belonging to 18,517 individuals were exposed during the network intrusion[5][11].

How it came to light

The extortion campaign became known on July 1, 2026, when ShinyHunters added Fluke to its leak site[4][7]. The leaked files were subsequently analyzed and processed into the Have I Been Pwned database on July 15, 2026[8][12].

For the earlier network intrusion, Fluke discovered unauthorized access on September 29, 2025[10][11]. Following forensic analysis, Fluke began sending written breach notification letters to impacted individuals and state regulators, including the California Attorney General, on May 15, 2026[11].

What was exposed

The July 2026 leak published by ShinyHunters included 821,100 unique email addresses alongside corporate contact information, such as names, phone numbers, physical addresses, job titles, and employers[1][8]. The dataset also contained a large collection of customer support tickets[1].

The May 2026 disclosure involved sensitive records of 18,517 individuals, primarily current and former employees, job applicants, and benefit plan dependents[5]. Exposed fields in that incident included Social Security numbers, dates of birth, and self-identified disability status indicators[6][11].

Root cause

The initial intrusion between August and October 2025 occurred after an attacker exploited a vulnerability in a third-party business application used by Fluke[10][11]. The vulnerability allowed unauthorized access to a limited segment of Fluke's internal network[11].

The precise initial access vector used to exfiltrate the data published in the July 2026 ShinyHunters extortion campaign has not been disclosed[1][4].

What to do if you were affected

Individuals whose email addresses or business details were included in the customer support dataset should monitor for phishing and targeted social engineering attempts[1][2]. Fraudsters frequently utilize leaked corporate contact lists to craft convincing scam emails or impersonation attacks[2].

Individuals who received Fluke's May 2026 notification regarding exposed Social Security numbers should place a fraud alert or credit freeze with credit bureaus[5][11]. Fluke offered affected individuals 24 months of complimentary identity protection and credit monitoring services through Epiq[11].

Further cited findings

These assertions carry their own citations but could not be matched to a passage above.

  • Threat group ShinyHunters published over 100GB of data containing corporate contact details and customer support tickets across 821,100 accounts[1][4]
  • Fluke also notified 18,517 individuals regarding the earlier network breach that exposed Social Security numbers and disability indicators[5][6]

Sources

Every numbered marker above points at one of these. Links open in a new tab and are references, not endorsements.

  1. haveibeenpwned.com
  2. malwarebytes.com
  3. federmanlaw.com
  4. eevblog.com
  5. russellandhill.com
  6. consumer.zlk.comzlk.com
  7. ransomware.live
  8. dwm.gkavach.comgkavach.com
  9. dapeer.com
  10. classaction.org
  11. cdn.prod.website-files.comwebsite-files.com
  12. bsky.app

Were you caught in this breach?

Search your email, phone number or username against every record CheckLeaked indexes.

Check my data