Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Jul 30, 2026 · 7 min read

Fluke Breach Leaked 821,100 Customer Records

ShinyHunters demanded payment, Fluke declined, and 100GB hit the leak site. The dangerous part is not the addresses — it is the support tickets attached to them.

Fluke makes the multimeter clipped to an electrician's belt and the thermal camera a plant engineer carries into a substation. In July 2026 it became a line item on an extortion leak site. ShinyHunters demanded payment, Fluke declined, and more than 100GB went public. Two weeks later Have I Been Pwned loaded 821,100 records from that dump. If you ever filed a support case with Fluke, your address is the least interesting thing in there.

Key Takeaways

  • Have I Been Pwned added the Fluke breach on 15 July 2026 with 821,100 pwned accounts.
  • HIBP lists six compromised data classes: email addresses, employers, job titles, names, physical addresses and support tickets.
  • ShinyHunters published more than 100GB after Fluke declined to negotiate, claiming on its leak site that the haul covers over 21 million Salesforce records.
  • Neither Fluke nor parent company Fortive had issued a statement when BreachNews reported the listing on 2 July 2026.
  • This is Fluke's second breach disclosure of 2026; in May it notified 18,517 people of an intrusion running from 10 August to 7 October 2025.
A digital multimeter and test leads on an industrial workbench beside a laptop showing an open support ticket, representing leaked Fluke customer service records

What Happened to Fluke?

Fluke Corporation, the Everett, Washington maker of test and measurement instruments and a subsidiary of Fortive, was hit by a ShinyHunters extortion demand in early July 2026 and had its data dumped when it refused to pay.

The listing went up on 2 July alongside Ingram Content Group, according to BreachNews, with the group claiming more than 21 million Salesforce records containing PII and posting its usual grievance: the company "failed to reach an agreement with us despite our incredible patience." That claim was unverified, and no statement came from Fluke or Fortive.

Verification arrived elsewhere. On 15 July, Have I Been Pwned published the Fluke entry with 821,100 accounts. Mind the arithmetic gap: 21 million claimed records against 821,100 unique addresses is a ratio near 26 to 1. HIBP counts distinct humans, a Salesforce export counts rows, and one customer with a decade of warranty claims generates dozens of them. Twenty one million records is not twenty one million people — it is 821,100 people described in exhausting detail.

What Was Actually in the Data?

HIBP lists six compromised data classes for Fluke: email addresses, employers, job titles, names, physical addresses and support tickets.

The description is short and specific. The corpus "contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present." German outlet heise online, covering the HIBP addition, reported the same Salesforce origin and warned the material suits "targeted and more credible phishing campaigns aimed at Fluke customers."

Fluke sells to utilities, hospital biomedical departments and semiconductor fabs, so the employer column maps who maintains critical equipment and where.

Why Are Support Tickets Worse Than a Password Dump?

A password dump gives an attacker one guess at your account; a support ticket gives them a script.

Credential dumps are commodity. When 183 million passwords surfaced from infostealer logs, the defense was mechanical: rotate, deduplicate, turn on MFA. A support case cannot be rotated. It is a verbatim record of a conversation, and it usually carries:

  • Serial and model numbers for instruments sitting in your facility, plus purchase and calibration dates.
  • Deployment context — which building, which line, which substation, often with photos and firmware versions.
  • Internal contacts named in the thread: your procurement lead, your calibration manager, the distributor rep.
  • Your own words describing a fault, in your writing style, with the case number and timestamps.

Most coverage leads with the 100GB figure. Size is the least useful number here. The useful one is that a stranger can open an email with a sentence only a real Fluke customer should know.

How Does the ShinyHunters Extortion Pattern Work?

Steal from a SaaS tenant, demand payment privately, then publish everything on a leak site when the deadline passes.

The 2026 wave runs on voice phishing, not exploits. Attackers call employees, talk them through authorizing a malicious OAuth application, then pull Salesforce objects wholesale. BleepingComputer documented the group launching a Salesforce leak site to extort 39 companies, with ransom notes carrying a Bitcoin address and a 72 hour deadline, plus SMS harassment and DDoS pressure.

Fluke is a data point in a run, not an outlier. Cushman & Wakefield lost 50GB to the same phone driven playbook. Sysco saw 2.7 million addresses dumped after its deadline expired. Madison Square Garden's facial recognition files went the same way. Refusing to pay is the right call, and it does nothing for you: your record simply moves from a private dataset to a public one. Other crews run the identical playbook — ExfilSquad published UK government and police contact databases the same way after its demands went unmet.

What Would a Follow On Lure Look Like?

It would look like a reply, not a pitch — and it would arrive in the inbox you actually use for work.

Picture it. Subject: "RE: Case 04891233 — 87V calibration drift." The body quotes the symptom you described eighteen months ago, uses your name and title, names your site by city, then offers a link to "download your updated calibration certificate." The sender domain is a lookalike of a Fluke service partner. Nothing reads as generic, because nothing was guessed.

The escalated version skips you and goes at accounts payable: an invoice on a serial number your company owns, citing a case your colleague opened, with changed bank details. Business email compromise fails on plausibility, and a leaked case history is plausibility in bulk. Report attempts to the FBI's Internet Crime Complaint Center.

What Should You Do Now?

Assume the data is permanent and change behaviour instead of trying to claw it back.

  • Check your exposure. Search your work and personal addresses on Have I Been Pwned. The entry is verified, so a hit is a fact rather than a guess.
  • Rotate anything reused. No passwords appear in this set, but if the leaked address shares a password anywhere else, change it.
  • Move to phishing resistant MFA. Security keys and passkeys survive the relay attacks that SMS codes and push prompts do not, and CISA ranks the options in its guidance on implementing phishing resistant MFA.
  • Treat every Fluke referencing message as suspect for a year. A correct case number is now evidence of a leak, not of legitimacy — same for a caller who knows your service history.
  • Verify out of band and warn procurement. Call the number on your original purchase order, never the one inside the message, and freeze every bank detail change behind a callback to a known contact.

Why Email Users Should Care

Breach fatigue trained people to score leaks by what was stolen: passwords bad, card numbers worse, email addresses shrug. That scale measures the wrong thing. Whether you get robbed next quarter depends less on the sensitivity of a field than on how much context an attacker holds when writing to you.

Generic lures die at the sniff test because one detail lands wrong — your name spelled oddly, a product you never bought, an urgency that does not match how the vendor talks. Leaked support tickets delete those tells, and what arrives reads like continuity rather than first contact.

Leaked addresses also get monetized far below that tier. We covered how dumped ShinyHunters data feeds automated sextortion emails demanding around $2,000, where a single true detail makes a fabricated threat feel researched. Expect both ends: one precise invoice fraud attempt, and a lot of crude noise.

The Bottom Line

Fluke has disclosed two incidents in 2026. The earlier one, reported by Comparitech, covered 18,517 people whose Social Security numbers were exposed by an intruder holding network access from 10 August to 7 October 2025. The July dump touches roughly 44 times as many people, with data that is individually harmless and collectively a phishing kit. The first warrants credit monitoring. The second warrants a change in how you read your inbox.

Sources: Have I Been Pwned, Fluke breach entry, heise online, 821,100 records from Fluke added to HIBP, BreachNews, ShinyHunters adds Ingram Content Group and Fluke Corporation to leak site, Sherlock Forensics, Fluke data breach July 2026, BleepingComputer, ShinyHunters launches Salesforce data leak site, Comparitech, Fluke Corp notifies 18,000+ people of data breach, and CISA, Implementing Phishing Resistant MFA.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.