Data Breach · Explainer

“Disney Internal 37M (Slack)” Breach Alert: Why People Are Getting It and What Leaked

Published October 8, 2026

People whose email addresses turn up in dark web monitoring scans are receiving alerts naming a “Disney Internal 37M (Slack)” breach, which traces to the July 2024 leak of Disney’s internal Slack data rather than a new hack. A proposed employee class action over that leak settled and was dismissed in Los Angeles without a public claim process, so there is nothing to claim.

Data breach warning on a computer screen
▼ Allegations Only · Case Dismissed

This article describes a class action complaint. The claims in it are unproven allegations. The Walt Disney Company was never found liable, no class was certified, the case was dismissed after a settlement whose terms are not public, and there is nothing to claim. This page is informational and is not legal advice.

What Is the “Disney Internal 37M (Slack)” Alert?

Dark web monitoring services, the kind built into password managers, email providers, credit bureaus and identity-protection apps, scan leaked files for their users’ email addresses and send an alert when they find a match. Alerts with the breach name “Disney Internal 37M (Slack)” and a “date found” of August 31, 2026 are pointing to a copy of the data stolen from Disney’s internal Slack workspace in 2024. The hacker posted that data on a forum on July 12, 2024, under the title “DISNEY INTERNAL SLACK.” The date on the alert is when the monitoring service found the copy, not when anything was taken from Disney, and no new Disney breach has been reported.

Status Old Leak Recirculating · Lawsuit Dismissed Data stolen in May 2024 and posted July 12, 2024
What Leaked About 1.1 terabytes of internal Slack data Messages, spreadsheets and PDFs from thousands of Disney Slack channels
Can I Claim? No — nothing to claim The employee lawsuit settled privately; no class fund or claim form

What Happened in the Disney Slack Leak?

According to federal prosecutors, Ryan Mitchell Kramer of Santa Clarita, California, built malware in early 2024 and posted it on GitHub and other sites disguised as an AI image-generation tool. A Disney employee downloaded it in the spring of 2024, giving Kramer access to the employee’s computer and saved passwords. Kramer used those credentials to get into Disney’s Slack and, in May 2024, downloaded about 1.1 terabytes of data from thousands of channels.

In July 2024, posing as a Russia-based hacktivist group called “NullBulge,” Kramer threatened the employee by email and Discord. When the employee did not respond, he posted the Slack files on a hacking forum along with the employee’s own bank, medical and personal information. Kramer pleaded guilty to accessing a computer and obtaining information and to threatening to damage a protected computer, and admitted using the same malware on two other people. He was sentenced in May 2026 to 15 months in federal prison and two years of supervised release. Disney told the court the attack caused it roughly $2.3 million in damages, according to Los Angeles magazine.

What Information Was in the Leaked Files?

Most of the data was Disney’s own work material: internal messages, unreleased projects, images, code and links to internal tools. Personal information was mixed in. The Wall Street Journal, as summarized in later coverage, reported that the dump contained more than 44 million Slack messages, about 18,800 spreadsheets and 13,000 PDFs, and that some messages included passport numbers, visa details, birthplaces and home addresses of Disney Cruise Line employees. Some spreadsheets reportedly listed names, addresses and phone numbers of Disney Cruise Line passengers.

That mix explains why people outside Disney are getting alerts. A Slack workspace holds email threads, vendor lists, guest records and shared files, so an outside email address can appear in the data without the person ever having worked for Disney. Whether an address appeared next to anything more sensitive depends on where it was found, which the alert service’s breach details usually describe.

Where Does the 37M Figure Come From?

Neither Disney nor federal prosecutors has published a 37 million figure. Prosecutors described the theft by size, about 1.1 terabytes, and press reports counted more than 44 million messages. The “37M” in the alert name appears to be the monitoring service’s own count of records in the copy it indexed, and OCA could not match it to any official number. As of October 8, 2026, the public Have I Been Pwned breach database did not list a Disney Slack breach, so the alert most likely comes from a commercial monitoring service with its own dark web sources.

Was There a Disney Data Breach Lawsuit?

Yes. Margel v. The Walt Disney Company, No. 24STCV25787, was filed on October 3, 2024, in Los Angeles County Superior Court against The Walt Disney Company and Disney California Adventure. The 32-page complaint seeks to represent people who gave Disney highly sensitive personal information in connection with their employment, a group it estimates in the thousands. It alleges negligence, breach of implied contract and violations of privacy law, and claims that Disney failed to prevent the breach and did not adequately tell affected people what was taken. The plaintiff asks for damages and for Disney to strengthen its data security.

These were allegations that no court ruled on, and Disney did not comment to the Los Angeles Times when the suit was filed. According to the court’s docket, a Notice of Settlement was filed on September 19, 2025, dismissal papers followed in February 2026, and the case is now marked disposed. The settlement terms have not been made public. OCA has found no motion for preliminary approval, class notice or settlement website, the steps California courts require before a class-wide settlement can pay class members, which suggests the case ended without a class settlement fund. There is no claim form for employees or anyone else.

What Do Consumer Agencies Say About Breach Alerts?

The Federal Trade Commission’s guidance on data breaches says the right response depends on what kind of information was exposed. For an email address alone, its guidance centers on changing any password that was reused, turning on two-factor authentication, and watching for phishing messages that mention the breach to seem legitimate. For leaked passport or Social Security numbers, the FTC points to IdentityTheft.gov, which lists steps by type of data.

Questions

Is “Disney Internal 37M (Slack)” a new Disney data breach?

No new Disney breach has been reported. The name matches the July 2024 leak of Disney’s internal Slack data, which was posted on a hacking forum under the title “DISNEY INTERNAL SLACK.” The “date found” on an alert is when the monitoring service came across a copy of the files, not when the data was taken.

Where does the 37M number come from?

Neither Disney nor federal prosecutors have published a 37 million figure. Prosecutors described about 1.1 terabytes of data from thousands of Slack channels, and press reports counted more than 44 million messages. The 37M label appears to be the monitoring service’s own count of records in the copy it found; OCA could not match it to any official number.

Is there a Disney Slack data breach settlement to claim?

No. A proposed class action, Margel v. The Walt Disney Company, was filed in Los Angeles County Superior Court in October 2024 on behalf of people who gave Disney personal information in connection with their employment. A notice of settlement was filed in September 2025 and the case was dismissed in February 2026, but no class was certified, no settlement terms were made public and no class notice or claim form was issued, so there is nothing to claim.

Who was behind the Disney Slack leak?

Ryan Mitchell Kramer of Santa Clarita, California, who posed as a hacktivist group called NullBulge. He pleaded guilty in federal court in Los Angeles to accessing a computer and obtaining information and to threatening to damage a protected computer, and in May 2026 he was sentenced to 15 months in prison.

Does the alert mean a password was leaked?

Not necessarily. An alert means the monitoring service found the email address somewhere in the leaked files. The Slack data was internal workplace messages and documents, so an outside email address could appear in a message, a spreadsheet or a shared file without any password attached. The alert service’s own breach details list which kinds of data it found.

Sources

• U.S. Attorney’s Office, Central District of California — plea agreement announcement
• Los Angeles magazine — May 2026 sentencing report
• Patch — sentencing report
• BleepingComputer — guilty plea and the “DISNEY INTERNAL SLACK” forum post
• Los Angeles Times — October 2024 report on the class action
• WDW News Today and Inside the Magic — coverage of the Margel complaint
• Malwarebytes — July 2024 analysis of the leak
• Federal Trade Commission — IdentityTheft.gov

For more class actions keep scrolling below.
Status Settled and dismissed; case disposed Notice of settlement September 19, 2025 · dismissal February 2026
Case Title Margel v. The Walt Disney Company
Case Number 24STCV25787
Court Los Angeles County Superior Court
Date Filed October 3, 2024
Criminal Case Hacker sentenced to 15 months U.S. District Court, Central District of California · May 2026

More on Disney Privacy Cases