In June 2026, Kodak confirmed that an unauthorized third party had temporarily accessed a limited amount of company data, after the ShinyHunters extortion group claimed it had stolen more than 2.2 million records containing customer personal information and internal corporate data and listed the company with a June 18 deadline to respond.1 BleepingComputer 2026-06-17 Kodak confirmed unauthorized temporary access to a limited amount of data after ShinyHunters claimed 2.2 million records with a June 18 2026 deadline; the group's 2026 campaign spans Salesforce, Snowflake, and PeopleSoft. Open source 2 Malwarebytes 2026-06-18 ShinyHunters set a June 18 2026 ultimatum and relies on data theft and extortion rather than ransomware, using social engineering, bribery, and zero-day vulnerabilities. Open source Kodak did not directly attribute the intrusion to ShinyHunters and did not confirm whether attackers reached its internal network, leaving the true scope open.3 SafeState 2026-06-18 Kodak did not directly attribute the attack or confirm whether its internal network was reached; the incident fits ShinyHunters targeting of Salesforce, Snowflake customers, and Instructure via leak-site listings. Open source Why it matters: the case is a clean illustration of how a data-theft-and-extortion crew converts a modest intrusion at a legacy brand into leverage. We assess, with moderate confidence, that the gap between the 2.2 million claim and Kodak's limited characterization reflects ShinyHunters' deadline-driven pressure model rather than a resolved measure of the damage.1 BleepingComputer 2026-06-17 Kodak confirmed unauthorized temporary access to a limited amount of data after ShinyHunters claimed 2.2 million records with a June 18 2026 deadline; the group's 2026 campaign spans Salesforce, Snowflake, and PeopleSoft. Open source
The drivers
ShinyHunters does not encrypt. Unlike ransomware crews that lock systems, the group steals data and monetizes the threat of publication, and in the Kodak case it set a hard deadline, warning Kodak to reach out by June 18, 2026 before the data would be leaked along with what it called digital problems.1 BleepingComputer 2026-06-17 Kodak confirmed unauthorized temporary access to a limited amount of data after ShinyHunters claimed 2.2 million records with a June 18 2026 deadline; the group's 2026 campaign spans Salesforce, Snowflake, and PeopleSoft. Open source 2 Malwarebytes 2026-06-18 ShinyHunters set a June 18 2026 ultimatum and relies on data theft and extortion rather than ransomware, using social engineering, bribery, and zero-day vulnerabilities. Open source Its toolkit is documented: social engineering, bribery of insiders, and zero-day vulnerabilities.2 Malwarebytes 2026-06-18 ShinyHunters set a June 18 2026 ultimatum and relies on data theft and extortion rather than ransomware, using social engineering, bribery, and zero-day vulnerabilities. Open source The deadline is the product. By listing a victim and starting a countdown, the group manufactures urgency before it has to prove exactly what it holds, which is why a 2.2 million record claim can coexist with a target that describes the access as limited.1 BleepingComputer 2026-06-17 Kodak confirmed unauthorized temporary access to a limited amount of data after ShinyHunters claimed 2.2 million records with a June 18 2026 deadline; the group's 2026 campaign spans Salesforce, Snowflake, and PeopleSoft. Open source
Kodak's response followed the now-standard script for a company caught in this model: acknowledge unauthorized access, characterize it as limited and contained, engage external cybersecurity experts, notify law enforcement, and decline to explain how the intrusion happened.1 BleepingComputer 2026-06-17 Kodak confirmed unauthorized temporary access to a limited amount of data after ShinyHunters claimed 2.2 million records with a June 18 2026 deadline; the group's 2026 campaign spans Salesforce, Snowflake, and PeopleSoft. Open source Kodak stated there was no threat to its systems or operations, but did not confirm whether the attackers reached the internal network, which is the ambiguity the extortion model exploits.3 SafeState 2026-06-18 Kodak did not directly attribute the attack or confirm whether its internal network was reached; the incident fits ShinyHunters targeting of Salesforce, Snowflake customers, and Instructure via leak-site listings. Open source
Second order effects and the ledger
The Kodak incident is one node in a wider 2026 campaign. ShinyHunters has targeted Salesforce, Snowflake customers, organizations running Oracle PeopleSoft, and the education platform Instructure, typically using leak-site listings as the pressure lever before any negotiation.1 BleepingComputer 2026-06-17 Kodak confirmed unauthorized temporary access to a limited amount of data after ShinyHunters claimed 2.2 million records with a June 18 2026 deadline; the group's 2026 campaign spans Salesforce, Snowflake, and PeopleSoft. Open source 3 SafeState 2026-06-18 Kodak did not directly attribute the attack or confirm whether its internal network was reached; the incident fits ShinyHunters targeting of Salesforce, Snowflake customers, and Instructure via leak-site listings. Open source That pattern names the ledger. Who gains: the group itself, which has built a repeatable pipeline where the marginal cost of adding a victim like Kodak is low and the leverage comes from the threat, not from operational disruption.2 Malwarebytes 2026-06-18 ShinyHunters set a June 18 2026 ultimatum and relies on data theft and extortion rather than ransomware, using social engineering, bribery, and zero-day vulnerabilities. Open source
Who loses: legacy brands with recognizable names and, often, modest security budgets, which make attractive targets because the reputational stakes of a public leak are high relative to the effort required to breach them.1 BleepingComputer 2026-06-17 Kodak confirmed unauthorized temporary access to a limited amount of data after ShinyHunters claimed 2.2 million records with a June 18 2026 deadline; the group's 2026 campaign spans Salesforce, Snowflake, and PeopleSoft. Open source Kodak's customers lose in the concrete sense that personal information may be exposed, and the standard downstream risk is phishing that references the breach, which is why the practical guidance centers on credential hygiene and watching for breach-themed lures.2 Malwarebytes 2026-06-18 ShinyHunters set a June 18 2026 ultimatum and relies on data theft and extortion rather than ransomware, using social engineering, bribery, and zero-day vulnerabilities. Open source There is a structural loser too: the disclosure norm itself. When a company can say access was limited while an attacker claims millions of records, and neither side substantiates its figure at the deadline, the public cannot calibrate the real exposure, and that ambiguity is a feature of the model rather than a temporary information gap.3 SafeState 2026-06-18 Kodak did not directly attribute the attack or confirm whether its internal network was reached; the incident fits ShinyHunters targeting of Salesforce, Snowflake customers, and Instructure via leak-site listings. Open source
The counter-case
The assessment that the 2.2 million figure is pressure rather than a measured haul could be wrong if ShinyHunters follows through and publishes a dataset of that scale. The group has a track record across many victims, so the claim is not idle, and if a full leak materializes then Kodak's limited characterization was the understatement, not the attacker's number the exaggeration.3 SafeState 2026-06-18 Kodak did not directly attribute the attack or confirm whether its internal network was reached; the incident fits ShinyHunters targeting of Salesforce, Snowflake customers, and Instructure via leak-site listings. Open source For the pressure-model reading to fail, the published data would need to match or approach the claimed volume and clearly include the internal corporate records the group described. The counterweight is that ShinyHunters routinely withholds proof before a deadline and uses the threat of publication as leverage rather than committing to evidence up front, which is exactly why the claim and the confirmation diverge at this stage.1 BleepingComputer 2026-06-17 Kodak confirmed unauthorized temporary access to a limited amount of data after ShinyHunters claimed 2.2 million records with a June 18 2026 deadline; the group's 2026 campaign spans Salesforce, Snowflake, and PeopleSoft. Open source
What to watch
- The data actually publishes. If ShinyHunters releases a Kodak dataset after the June 18 deadline, its contents and volume will show whether the 2.2 million claim was real; no publication would suggest quiet negotiation or a bluff.2 Malwarebytes 2026-06-18 ShinyHunters set a June 18 2026 ultimatum and relies on data theft and extortion rather than ransomware, using social engineering, bribery, and zero-day vulnerabilities. Open source
- Kodak clarifies scope. A follow-up disclosure specifying what data and how many individuals were affected would replace the current ambiguity; continued silence keeps the extortion leverage intact.1 BleepingComputer 2026-06-17 Kodak confirmed unauthorized temporary access to a limited amount of data after ShinyHunters claimed 2.2 million records with a June 18 2026 deadline; the group's 2026 campaign spans Salesforce, Snowflake, and PeopleSoft. Open source
- The entry vector surfaces. Kodak has not said how the breach occurred; identification of the vector, whether social engineering, an insider, or a zero-day, would show which part of the ShinyHunters toolkit was used and whether third-party platforms were involved.2 Malwarebytes 2026-06-18 ShinyHunters set a June 18 2026 ultimatum and relies on data theft and extortion rather than ransomware, using social engineering, bribery, and zero-day vulnerabilities. Open source
- The campaign adds names. New legacy brands appearing on ShinyHunters' leak site in the following months would confirm the pipeline is still running and that soft-target selection is deliberate.3 SafeState 2026-06-18 Kodak did not directly attribute the attack or confirm whether its internal network was reached; the incident fits ShinyHunters targeting of Salesforce, Snowflake customers, and Instructure via leak-site listings. Open source