← Back to Home

Kemper Data Breach

Verified Breach
Apr 14, 2026 Breach Date
269,299 Accounts Affected
6 Data Types Exposed
May 28, 2026 Added to HIBP
About This Breach
In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign. The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique email addresses were names, phone numbers, physical addresses and partial payment card data including the last 4 digits, expiry dates and card brands. Kemper confirmed the incident and stated they had engaged third-party cybersecurity experts and notified law enforcement.
Compromised Data Types
Email addresses Names Partial credit card data Phone numbers Physical addresses Purchases
Check If You Were Affected

Were you part of the Kemper breach?

Has your email been exposed in a breach?