Fluke data breach, and their past disclosure woes
Fluke / Fluke.com has reportedly faced a data breach. No direct communication has been confirmed to have occurred between affected entities.
Status:
Confirmed
First report observed: July 1st 2026
Date confirmed by company: No direct communication observed.
Data here may not be accurate, as it is manually collected by a single person. Use at your own risk :p
Fluke / Fluke.com has reportedly faced a data breach. No direct communication has been observed to have occurred between affected entities nor reported by any third parties, and as such we cannot confirm it here.
While we expect relevant stakeholders were informed, we are also aware that they may have a history of withholding notices of a breach.
See below an excerpt from an alleged data breach notification, showing a delay of almost an entire year between breach and notification!
On September 29, 2025, we learned that a criminal actor exploited a vulnerability in a third-party application used by us and was able to access a limited segment of our network.
Upon discovering the incident, we immediately launched a thorough investigation with the support of a leading cybersecurity firm.
We also engaged a leading data forensics firm to analyze the contents of the data that may have been accessed without authorization.
Their data analysis was completed on May 8, 2026, and this notice has not been delayed as a result of a law enforcement investigation.
HOW DOES AND IMMEDIATE AND THOROUGH INVESTIGATION LEAD TO A 6 MONTH NOTICE PERIOD?????? BEAR IN MIND THAT THIS BREACH (allegedly) INCLUDED PII SUCH AS SSNs, BIRTHDATES AND DISABILITY STATUS?????????????????????????????????????????
Anyway, back to the current breach:
Objects included in this breach has been reported to include:
- Corporate contact information, incl:
- Email addresses
- Employers
- Job titles
- Names
- Physical addresses
- Support cases
The listing of corporate contact information may be useful in reconnaissance and phishing activity by a threat actor.
I am unsure of the content of the support cases as further digging and verification has not been performed. It could further potential phishing activity. It is likely suuuuper helpful for recon activity too. This is speculation though, as again, I don't even know what was in the support cases.
It seems like nobody cares anyway, honestly, neither do I. The slop reporting on data breaches drives me crazy. As if this article is any different....
I don't have anything to shill, but I do ask that you pls leave a comment if you read this article. Ideally a hate comment!
Alternatively, email: comments@verifiedbreaches.com
[Current breach data]
- https://haveibeenpwned.com/Breach/Fluke
- https://www.dexpose.io/shinyhunters-breach-fluke-corporation/
[Data on stupidly long disclosure of past breach containing arguably way worse data]
- https://today.westlaw.com/Document/Idbbd4cdf643011f19af0b4392b5a3e5c/View/FullText.html
- https://www.classaction.org/data-breach-lawsuits/fluke-corporation-may-2026
- https://www.pacermonitor.com/public/case/65041407/Stewart_v_Fluke_Corporation
We consider this breach 'confirmed' given the surrounding reporting overwhelmingly suggesting that this data exists as published by the ShinyHunters group.
More sources were considered. However, these appeared to be the most accurate and reputable.
Further sources do not appear relevant, nor do they list new information.