pb.com data breach

pb.com

What Happened

On April 18, 2026, the ransomware group ShinyHunters breached Pitney Bowes Inc. (pb.com), a US-based logistics technology company, through a phishing attack that compromised an employee email account and gained unauthorized access to their Salesforce customer relationship management environment. The breach exposed over 25 million Salesforce records containing personally identifiable information, though public data breach trackers confirmed 8.2 million unique email addresses were included in the leaked data dump, along with names, phone numbers, physical addresses, and a subset of employee records with job titles. The breach was discovered on April 19, 2026, and ShinyHunters issued a final extortion warning on April 18 demanding payment by April 21 before threatening to publicly release the data. After negotiations allegedly failed, the group publicly released the data, and Pitney Bowes confirmed on April 9 that it had identified the unauthorized access, immediately secured the environment, and engaged cybersecurity experts and law enforcement to investigate.

Compromised Assets

  • email
  • phone
  • ip
  • full name
  • password

Check your company's
exposed credentials

Enter your work email to instantly access a free account
and see your company’s exposed credentials.

Related Breaches