Eye care company Alcon was named in a ShinyHunters "pay or leak" extortion campaign in August 2026. The group went on to publish the data, and Have I Been Pwned verified 218,395 unique email addresses in it, along with names, phone numbers and physical addresses. Have I Been Pwned describes the fields as largely corporate B2B contact data — so the people affected are mainly contacts at practices, clinics and suppliers rather than retail customers. Alcon has not publicly acknowledged the incident and appears not to have notified those affected, meaning anyone in the dataset will not hear about it from the company. Because the data was published rather than sold, it is freely available to anyone, and the combination of name, business address and phone number makes targeted calls and invoice phishing very convincing.
After a breach: the part most people skip
A leaked email and phone number don't just sit in one dump — data brokers buy breach data, merge it with public records, and resell it. That's why the spam calls and phishing texts keep coming months later. Deleting your data from the breached company is only the first step; getting it out of the broker network is what actually stops the follow-on damage.