The images in this article were generated with artificial intelligence. How we publish
Kodak has confirmed that he is investigating unauthorized access to "a limited amount" of data and has hired external cyber security experts to determine what was copied and how it happened. Although the company insists that its systems and operations are not at risk, the extortion group known as ShinyHunters has published on its web dark leaks site a claim that claims to have exfiltered more than 2.2 million records with personal identifiable information (PII) of customers and internal corporate data, and threatened to publish them if Kodak did not contact before 18 June 2026.
The episode replaces on the table two realities that are no longer extraordinary: on the one hand, that even centenary companies with valuable assets and security resources can suffer gaps; and on the other, that specialized extortion groups take advantage of both direct failures and third-party vectors and cloud services to maximize their impact. ShinyHunters, whose activity and modus operandi are documented in public sources such as Wikipedia has been linked to numerous previous intrusions and the publication of large volumes of stolen data.

Beyond the media varnish, the real risk for Kodak customers and partners includes the possibility of fraud, identity supplanting and phishing campaigns directed with filtered personal data. For the company itself, the potential consequences range from regulatory penalties for data protection to loss of commercial confidence and significant remediation costs. The threat of extortion filtering also alters decision-making: to pay or not to pay does not guarantee the destruction of copies or prevent their resale in the clandestine market.
From the technical and management point of view, this type of incident often involves failures in more than one layer: committed credentials, excessive permits in SaaS integrations, lack of network segmentation or insufficient detection in EDR / SIEM tools. In addition, the forensic investigation must determine whether the attackers obtained direct access to internal systems or whether the exfiltration came from suppliers and third parties integrated into the company's digital ecosystem.
For companies and IT managers there are immediate and follow-up measures that reduce damage and accelerate recovery. It is appropriate to activate the incident response plan, preserve logs and evidence for forensic investigation, reset privileged credentials and force multifactor authentication where possible. In the medium term it is essential to review application permissions and service accounts, to segment critical networks, and to conduct integration audits with third parties to limit the chain break that allow campaigns such as those attributed to ShinyHunters.
At the legal and enforcement level, organizations should assess reporting obligations to regulators and clients according to jurisdiction, document measures taken and consider the provision of identity monitoring services to potentially affected persons. Coordination with security forces and the exchange of IoCs (indicators of commitment) with the incident response community can help to mitigate the re-use of credentials for other objectives.

Consumers and customers of affected companies can also take concrete steps: monitoring unusual communications, activating movement alerts in financial accounts, changing single passwords and reviewing credit protection offers if the companies concerned offer them. Individual prevention begins with mistrust of unsolicited emails and messages that use filtered data to make the deception more credible.
This event illustrates why organizations of all sizes should invest in the detection and simulation capabilities of attacks that test rules of IMS and EDR before an opponent does. Official resources and good practices, such as the guidelines on extortion and response to incidents published by agencies such as CISA or the NIST response criteria, offer practical road maps to coordinate mitigation, communication and recovery.
Finally, the strategic lesson is clear: cybersecurity is both technical and organizational. Resilience depends on governance that combines prevention, early detection, coordinated response and controls over cloud suppliers and services. For companies that depend on external integration and customer data, the priority is to reduce the attack surface and ensure that, when an incident occurs, the response is rapid, documented and aimed at protecting the people concerned and restoring the operation with transparency.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...