Never lose a customer to a missed message
An AI agent trained on your own business, replying in seconds, in any language, on every channel your customers already use.
A hacking group best known for hitting healthcare and telecom giants has claimed another target. The American Tower data breach was disclosed after ShinyHunters exfiltrated more than 5.2 million records on September 3. It adds one of the world’s largest wireless infrastructure companies to this year’s list of major breaches.
American Tower operates thousands of communications towers that carry mobile network traffic across the United States and internationally. That makes it a less visible but critical piece of the infrastructure keeping phones connected. The company has not yet disclosed the full scope of what data was taken or how the intrusion occurred.

What we know about the American Tower data breach
ShinyHunters claimed responsibility for exfiltrating the records on September 3. Researchers have linked the group to a string of major breaches this year. The group has built a pattern of targeting large enterprises that hold significant volumes of customer and operational data. It then either sells the stolen records or uses them as leverage in extortion attempts.
Security researchers tracking the group’s activity say American Tower fits a recurring profile among ShinyHunters targets this year. These are large infrastructure and services companies. Their breaches ripple outward to customers and partners who never had a direct relationship with the hacking group itself.
How this fits a brutal year for corporate breaches
American Tower joins a list of major 2026 breach victims. That list already includes McKesson, the healthcare distributor whose data theft affected 284 million patient records. It also includes Manchester Airports Group, where a breach exposed contact details for 8.8 million people. ShinyHunters has been linked to several of the year’s largest disclosed incidents.
Cybersecurity researchers who track ransomware and extortion trends say infrastructure and logistics companies have become increasingly attractive targets. Their data often includes sensitive operational details alongside conventional customer records. Attackers can use both for extortion beyond a simple data sale.
What comes next for affected parties
American Tower has not yet said whether it will offer credit monitoring or other remediation. That step has become standard practice for major disclosed breaches. That step has become standard practice for major disclosed breaches in recent years. The company plans to file required disclosures with regulators once its internal investigation is complete.
Companies that rely on American Tower’s infrastructure for network connectivity are also watching closely. They want to know whether the breach extended into operational or network configuration data. That kind of exposure could carry broader implications for telecom reliability.
What businesses should take from this breach
Security professionals point to the recurring pattern behind ShinyHunters’ campaigns. It is a reminder that large organizations across every sector hold data worth targeting, not just technology or healthcare companies. Security professionals are urging infrastructure providers to audit third-party access and legacy systems. Several of this year’s largest breaches trace back to compromised third-party applications. The attacks did not target the primary victim’s own systems directly.
Why telecom infrastructure breaches carry extra risk
Companies like American Tower sit in an unusual position within the technology supply chain. They do not sell phones or run consumer-facing apps. But the towers and infrastructure they operate carry traffic for mobile carriers. Hundreds of millions of people rely on that traffic daily. A breach at this level of the stack can expose customer or vendor records. It could also expose network architecture details valuable to anyone looking to disrupt or surveil communications infrastructure.
Regulators overseeing critical infrastructure have increasingly pushed telecom-adjacent companies to adopt stricter breach disclosure timelines. That follows several recent incidents where delayed disclosure left customers and partners unaware of exposure. Some did not learn of the intrusion for weeks or months.
Analysts following ShinyHunters’ campaigns this year note the group frequently waits weeks before publicly claiming a breach. It uses that time to negotiate directly with victims. Only when talks fail does it turn to public disclosure or a data sale. That pattern makes early, independent verification of any breach claim difficult until the affected company confirms details itself.
What American Tower does and why it matters
American Tower owns and leases communications towers to wireless carriers around the world. It operates sites across North America, Latin America, Africa, Europe and Asia. Carriers pay to mount their antennas on its infrastructure rather than building their own towers, making the company a quiet but essential landlord for the mobile networks people use daily.
Frequently asked questions
What happened in the American Tower data breach?
The hacking group ShinyHunters says it exfiltrated more than 5.2 million records from American Tower Corporation on September 3, 2026.
Who is ShinyHunters?
ShinyHunters is a hacking group tied to several of 2026’s largest corporate data breaches. Its targets have included McKesson and other major companies.
What data was taken?
American Tower has not yet disclosed the full scope of the stolen records. The company has not confirmed exactly what categories of data were affected.
Should customers take action?
Affected individuals should watch for official notification from American Tower. They should also monitor accounts for unusual activity until remediation steps are clarified.
For more on this year’s wave of major technology incidents, see our coverage of the Microsoft 365 outage and the simultaneous AI chatbot outages earlier this month.
Sources
- Tech.co — Data Breaches That Have Happened This Year (2026 Update). tech.co
- Bitsight — Data Breach Tracker 2026: Latest Incidents & Statistics. bitsight.com
- ACI Learning — The Biggest Cybersecurity Breaches of 2026 So Far. acilearning.com
Verification your users actually receive.
Send one-time passcodes over WhatsApp with a single API call. Replio can generate, hash and verify the code for you.

