Breach Intelligence Report 24 Sep 2026

Inter-Con Security’s Salesforce Data Breach Hit 276,352 Records

HEROIC
HEROIC Threat Intelligence Team
Email Address Username First Name Last Phone Number
Security https://www.icsecurity.com
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 276,352
Source Type Database
Origin United States
Password Type plaintext

In June 2026, Inter-Con Security, a physical security and manned guarding firm operating across the United States, confirmed that 276,352 records had been exfiltrated from its Salesforce CRM. The exposed data covers contacts, sales leads and customers, and includes names, phone numbers and email addresses tied to real people who had dealings with the company.

The records were later distributed through a cybercrime channel as part of a wider campaign targeting Salesforce customers, and HEROIC's scanner is already checking email addresses against this data.


Why This Is Dangerous

A physical security company's contact list is a useful tool for a scammer, since it lets them impersonate Inter-Con Security or one of its clients convincingly, using real names and phone numbers to add credibility to a phishing attempt or a fraudulent call.


What Was Exposed

  • Email addresses give attackers a direct channel for phishing messages.
  • Usernames can help an attacker guess or target related accounts.
  • First and last names allow messages to be personalized, making scams more convincing.
  • Phone numbers open the door to targeted calls, texts and voice phishing attempts.

Why This Matters

Because no passwords were part of this exposure, direct account takeover is not the immediate concern. The bigger risk is social engineering, where an attacker uses accurate personal details to convince a target that a call, text or email is legitimate before asking for sensitive information or payment.


How a Database Breach Like This Happens

This exposure did not come from malware on a personal device. It came from Inter-Con Security's own Salesforce environment, part of a broader extortion campaign that has targeted multiple companies' CRM systems, with the stolen data later distributed to other cybercriminals.


Should You Watch for Contact From Inter-Con Security?

Scan your email to see if your address is part of this exposure. If it is, be cautious of unexpected calls or messages referencing this company, and avoid sharing further personal details until you can confirm who you are actually speaking with. This applies whether the contact reaches a personal or a work email.

Breach Breakdown

Domain https://www.icsecurity.com
Leaked Data Email Address,Username,First Name,Last Name,Phone Number
Password Types plaintext
Date Leaked 24 Sep 2026
Check in 5 seconds

276,352 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,171 scanned today
Breach Rank #N/A by affected users
Impact Score
11
sensitivity + scale + recency
Est. Financial Impact $2.0M fraud, phishing & misuse risk
Scan your email Free →

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance