Fluke Corporation, which describes itself as a multinational maker of electronic test and measurement tools (www.fluke.com), is tied to a July 1, 2026 ShinyHunters data leak that leaksear.ch has indexed as 30,240 records (leaksear.ch metadata). The indexed subset contains corporate account identifiers, email addresses, account metadata, and saved-browser credential fields (leaksear.ch metadata), while Have I Been Pwned lists the broader Fluke breach at 821.1K affected accounts (haveibeenpwned.com).
What happened
Public reporting ties the exposure to a ShinyHunters extortion leak. BreachNews reported that ShinyHunters added Fluke Corporation to its leak site, alleged failed ransom negotiations, and claimed it had stolen more than 100 GB of data, including more than 21 million Salesforce records (breachnews.com).
BreachNews also wrote that it had not independently verified the group’s claims or the authenticity of the purported data, and the public reports cited here do not establish the initial access route (breachnews.com). Have I Been Pwned describes the broader corpus as more than 100 GB of data allegedly taken from Fluke, containing largely corporate contact information, over 800,000 unique email addresses, and a large collection of support cases (haveibeenpwned.com).
The leaksear.ch entry was indexed on July 28, 2026 and is an indexed subset, not a claim that the entire public corpus is limited to 30,240 records (leaksear.ch metadata).
What data was exposed
The leaksear.ch indexed fields for this subset are email, name, username, and password (leaksear.ch metadata). The same records also store contextual account fields including company, creation type, Entra user ID, identities, user type, on-premises sync status, source table labels, and Edge saved-password counts, sites, URLs, and usernames (leaksear.ch metadata).
Have I Been Pwned classifies the broader Fluke breach data as email addresses, employers, job titles, names, physical addresses, and support tickets (haveibeenpwned.com).
Why this matters
Corporate emails, names, employers, account identifiers, and support-context records can make phishing and vendor impersonation more convincing. Password and saved-browser credential fields raise separate credential hygiene concerns for affected accounts, especially where a work password was reused (leaksear.ch metadata).
BleepingComputer reported on July 25, 2026 that email addresses from prior ShinyHunters leaks were being reused in fake ShinyHunters sextortion emails, showing how even contact-heavy breach data can be repurposed after publication (www.bleepingcomputer.com). Readers who used Fluke services, received Fluke support, or may appear in Fluke business records should check whether their own data appears in this leak.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include email, name, password, and username.