Kemper
Disclosed May 28, 20264 months ago269,299 accountsUnverified
In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign . The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique email addresses were names, phone numbers, physical addresses and partial payment card data includ
What is known
| People affected | 269,299 (accounts in the leaked data, per Have I Been Pwned) |
|---|---|
| Disclosed | May 28, 2026 |
| Happened | Apr 15, 2026 |
| Attack | Ransomware |
| Data exposed | Emails, Names, Payment cards, Phone numbers, Addresses, Financial |
| Sector | Tech |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| Have I Been Pwned: Kemperhaveibeenpwned.com · Aggregator | Aggregator |
Notices filed
| Where | Filed | People |
|---|---|---|
| Have I Been Pwnedaccounts in the data | May 28 | 269,299 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.