RTX Corporation, the aerospace and defense conglomerate formerly known as Raytheon Technologies, has begun notifying individuals that a security incident exposed their personal information, including Social Security numbers. Reporting drawn from RTX's filing with the Massachusetts Office of Consumer Affairs and Business Regulation puts the incident on June 25, 2026, with written notices mailed starting July 23, 2026 and the regulator notified on July 24, 2026. RTX has not publicly stated how many people were affected. A proposed class action filed by a former worker alleges roughly 1.5 million individuals were exposed, per Law360; that figure comes from plaintiffs' counsel, not from RTX, and should be treated as an allegation rather than a confirmed count.
What Happened
The clearest account of the timeline comes from teiss and Claim Depot, both working from the same Massachusetts regulatory filing. Both place the underlying security incident on June 25, 2026. Both say RTX began mailing notification letters on July 23, 2026 and reported the breach to Massachusetts regulators the following day, July 24. After discovery, RTX opened an internal investigation to determine the scope of the exposure and which categories of personal data were involved.
Accounts differ on the disclosure date. CyberNetSec.io describes a "July 31, 2026 disclosure" and places the intrusion in "late June 2026," which is consistent on the incident window but roughly a week later on the disclosure. The Massachusetts filing dates reported by teiss and Claim Depot are the more specific and better-corroborated timeline, and we weight them accordingly. DataBreachClassAction.io, which is running a plaintiff-side intake page on the matter, lists the date of breach as "not disclosed," a reminder that the regulatory notice itself is thin.
Separately, an RTX Form 8-K current report carrying a date of earliest event of July 23, 2026 appears in EDGAR mirrors, filed the same day notification letters went out. The excerpt available to us contains only the cover page and does not include the item text, so we cannot confirm from that document that the filing concerns this incident. Readers should not assume the 8-K is a breach disclosure until the item body is verified.
RTX has not publicly disclosed how the breach occurred, what systems were involved, or whether it has identified those responsible.
What Was Taken
The investigation concluded that the exposed data included:
- Full first and last names
- Mailing addresses
- Social Security numbers
Both teiss and Claim Depot report that same three-element set from the Massachusetts filing, and DataBreachClassAction.io independently lists names and Social Security numbers. That combination is the classic identity-theft triad: a name, a verified physical address, and the single federal identifier that is effectively impossible to rotate.
On volume, the record is genuinely unsettled. RTX itself has published no figure, and the Massachusetts notice as summarized by the intake sites contains none. The only number in circulation is the 1.5 million alleged in the ex-employee suit reported by Law360. Anyone citing that figure should attribute it to the complaint.
On population, sources also differ. teiss and the class action framing describe current and former employees. CyberNetSec.io says the compromised data belonged to employees "and possibly customers," a qualifier no other source repeats and one CyberNetSec.io does not source. Treat customer exposure as unconfirmed.
Why It Matters
RTX is one of the largest defense contractors on earth. A validated roster of names, home addresses and SSNs tied to that workforce is worth considerably more to a hostile intelligence service than it is to a card-fraud crew. It supports targeting selection, pretexting against cleared personnel, and the kind of long-horizon coercion work that identity-theft framing tends to obscure. CyberNetSec.io makes this point directly, flagging espionage, blackmail and targeted social engineering as risks beyond ordinary financial fraud, and it is the correct read regardless of who took the data.
Home mailing addresses deserve specific attention. For a cleared workforce, residential address disclosure is a physical-security and surveillance-enablement problem, not merely a junk-mail one. Combined with SSNs, it also enables high-fidelity impersonation against HR, payroll and benefits helpdesks, which is exactly the pivot an attacker would want next.
The legal exposure is already materializing. Console & Associates, P.C. is publicly soliciting affected RTX employees for a class action investigation, and at least one ex-worker suit is on file. Organizations should expect employee-data breaches at this scale to carry litigation and regulatory cost well past the notification window.
teiss notes RTX has disclosed prior cybersecurity incidents, including a 2025 ransomware attack that disrupted certain airport services, and assesses that this latest incident appears unrelated based on the differing dates and data categories involved.
The Attack Technique
There is no confirmed attack vector. RTX has not disclosed one, and no source in this set reports one.
CyberNetSec.io lists phishing, valid accounts, data from local system, and exfiltration over C2 channel as MITRE ATT&CK techniques associated with the incident. That mapping is explicitly speculative: the article states that without specifics "we can only speculate on likely TTPs based on common breach patterns." Defenders should not ingest those techniques as RTX-specific intelligence. They are a generic corporate-intrusion template.
Two adjacent campaigns are worth situating carefully, because both surface in coverage near this incident and neither has been linked to RTX by any source here:
- The Klue and Salesforce supply chain campaign. Obsidian Security analyzed a compromised Klue-Salesforce OAuth integration used to exfiltrate millions of CRM records across multiple victims, first reported by ReliaQuest on June 17, 2026. Multiple parties including Huntress, itself affected, attribute the activity to a new criminal group tracked as Icarus, though early speculation pointed at ShinyHunters. The pattern is over-permissioned, long-lived, poorly monitored OAuth tokens granting downstream access to crown-jewel SaaS data.
- The Nissan Americas employee-data breach. Rescana reports Nissan Americas disclosed a breach on June 25, 2026 affecting current and former employees, tied to CVE-2026-35273, a critical SSRF-to-RCE flaw in Oracle PeopleSoft PeopleTools exploited between May 27 and June 9, 2026 against exposed
/PSEMHUB/*and/PSIGW/HttpListeningConnectorendpoints. Attackers deployed MeshCentral disguised as Microsoft Azure services for persistence. ShinyHunters claimed responsibility; Mandiant confirmed zero-day exploitation.
The Nissan case is a close structural analogue to RTX: employee HR data including SSNs, a June 2026 window, a shared disclosure date of June 25. That resemblance is suggestive and nothing more. No source connects RTX to CVE-2026-35273, to Oracle PeopleSoft, to Klue, to Icarus, or to ShinyHunters. Any such link is currently unsupported.
What Organizations Should Do
- Audit HR and payroll platforms as tier-one assets. Both the Nissan case and this incident involve employee PII stores rather than customer databases. Inventory every system holding SSNs, confirm which are internet-facing, and apply crown-jewel monitoring to them.
- Patch Oracle PeopleSoft and restrict the exposed endpoints. If you run PeopleTools, remediate CVE-2026-35273 immediately and block external access to
/PSEMHUB/*and/PSIGW/HttpListeningConnector. Hunt retroactively for MeshCentral agents masquerading as Azure services. - Inventory and prune OAuth grants to your SaaS estate. Per Obsidian's Klue analysis, enumerate third-party integrations against Salesforce and equivalent systems, revoke stale grants, scope tokens down from broad read permissions, and alert on anomalous API-driven bulk reads.
- Harden identity-verification workflows against SSN-based pretexting. Assume a leaked name, address and SSN is sufficient to pass legacy helpdesk verification. Move HR, payroll and benefits support to out-of-band or device-bound verification rather than knowledge-based questions.
- Brief affected staff on targeted social engineering, not just credit freezes. For cleared or defense-adjacent workforces, warn explicitly about recruitment pretexts, spoofed HR correspondence to home addresses, and follow-on contact claiming to reference the breach.
- Track the notification and enrollment deadlines. RTX is offering affected individuals 24 months of Equifax Complete Premier, activated via a unique code in the notification letter. Per teiss, the enrollment window closes October 31, 2026. Employers with staff who may have received letters should surface that deadline internally.
- Prepare for the litigation tail. With plaintiff firms already soliciting claimants, preserve incident artifacts, log retention, and investigation records now rather than after a preservation demand arrives.
Sources: Defense Giant RTX Corporation Reports Employee Data... - CyberNetSe... | RTX Data Breach Exposes Social Security Numbers | RTX Corporation Data Breach Class Action Investigation DataBreachC... | Form 8-K - Current report | Ex-Worker Says RTX Exposed 1.5M In Employee Data Breach - Law360 | Technical Analysis of the Klue Attack: OAuth Abuse, Stale Integrati... | Nissan Americas Employee Data Breach Analysis: Oracle PeopleSoft Ze... | Aerospace and defense giant RTX Corp. discloses data breach exposin...