All Breaches
June 17, 2026 Verified Sensitive Record Technology

Kodak 2026 Data Breach

The Kodak 2026 data breach is a cyber incident in which Eastman Kodak Company confirmed that an unauthorized third party temporarily and illegally gained access to a limited amount of company data. Kodak said it opened an investigation with external cybersecurity experts, contained the incident, and was confident there was no continuing threat to its systems or operations.

BleepingComputer, SecurityWeek, and Kodak's Rochester-area local broadcaster WHEC/News10NBC directly reported the company spokesperson's confirmation. Kodak did not publicly disclose detailed types of accessed or copied data, the technical entry method, a precise timeline, or an affected-person count. LeakData preserves those uncertainties and displays the person total as zero, meaning unknown.

What Did Kodak Confirm?

The central fact confirmed by the company is that an unauthorized third party temporarily accessed a limited amount of Kodak company data. Kodak said it had recently discovered the event and was investigating what data had been accessed and copied. This wording confirms completed unauthorized data access, not merely an unsuccessful attack attempt.

Kodak's statement also expressed confidence that the incident was limited in scope and contained. The company said it saw no current threat to its systems or operations. That operational assessment does not negate the data access; it describes the company's view of ongoing technical and business impact at the time of the statement.

Why Is the Data Scope Kept Narrow?

Kodak's public confirmation did not identify specific categories such as customer, employee, supplier, financial, identity, contact, contract, or intellectual-property data. “A limited amount of company data” is the only verified data description currently available. LeakData therefore adds only limited company data to dataClasses and does not invent more specific personal fields.

The company said it continued examining which data had been viewed and copied. An investigation into possible copying does not prove that every accessed file was exfiltrated. At the same time, the explicit confirmation of illegal access makes this a real data breach; only the detailed content and affected-person scope remain undisclosed publicly.

The 2.2 Million Record Claim

The threat group known as ShinyHunters listed Kodak on its leak site and claimed to have obtained more than 2.2 million customer PII records and internal corporate data. BleepingComputer and SecurityWeek reported the allegation, but Kodak did not confirm the figure, the customer-data scope, or the group's description of the material. No independent unique-record analysis verified it either.

For that reason, 2.2 million is not entered as pwnCount and customer PII is not presented as a confirmed data class. Figures published during an extortion effort may include duplicates, test data, corporate rows, or records that do not map to distinct people. This record can be updated if the total is confirmed by the company, a regulator, or a verified data review.

Attacker and Technical Method

ShinyHunters claimed responsibility and threatened to publish the data, but Kodak did not identify an attacker in its own statement. The company used only the phrase unauthorized third party. LeakData retains the group name as contextual allegation and does not portray it as a definitive company attribution or law-enforcement conclusion.

Reports mention the group's previous Salesforce, Snowflake, third-party integration, and Oracle PeopleSoft campaigns. However, no PeopleSoft, Salesforce, compromised credential, social-engineering, zero-day, or ransomware method was confirmed in the Kodak incident. Technical methods observed at other victims cannot automatically be assigned to Kodak.

Response and Operational Status

Kodak brought in external cybersecurity experts to determine what data had been accessed and copied. The company notified law enforcement and said it continued supporting that investigation. It promised to share additional findings as appropriate; the available statement does not say that the forensic investigation had reached a final conclusion.

According to the company, the incident was contained and there was no continuing threat to systems or operations. No disruption to manufacturing, commercial-print services, materials and chemicals operations, or customer-facing products was confirmed. This record therefore documents the data access without adding unsupported business interruption or system-encryption effects.

How to Interpret This LeakData Record

The June 17, 2026 date in this record is the public-disclosure anchor for the company confirmation reported by BleepingComputer; it is not the attacker's initial-access date or Kodak's internal detection date. Kodak said only that it had discovered the incident recently. Estimating unknown technical dates would be misleading until a more precise timeline is released.

The verified conclusion is that Kodak data was temporarily accessed without authorization, the company viewed the scope as limited, contained the incident, engaged outside experts and law enforcement, and continued a detailed data review. Data types and person count were undisclosed; the 2.2 million customer-PII claim, ShinyHunters attribution, and entry method remain excluded from definitive fields because Kodak did not confirm them.

0
Affected Accounts
1
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

1
Limited amount of company data

Additional Information

Added DateJuly 27, 2026
Breach DateJune 17, 2026
Domainkodak.com
SourceTemporary unauthorized access to company data
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information