Fulcrum Real Estate Services Data Breach Exposes Social Security Numbers

Real Estate data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: June 2026

What Happened in the Fulcrum Real Estate Services Data Breach?

Fulcrum Real Estate Services, Inc. recently confirmed that it suffered a data breach involving sensitive personal information. The company filed formal notice with the Vermont Attorney General’s office, a step required whenever a business discovers that residents’ personal data has been compromised. This filing confirms that Social Security numbers were among the data types involved.

The notification does not specify the exact method attackers used to gain access. However, it does confirm that an investigation took place before Fulcrum notified regulators. Because the company waited until it understood the scope of the incident, the timeline suggests a forensic review occurred between discovery and public disclosure.

As a result of this review, Fulcrum determined that Social Security numbers had been exposed. Companies typically bring in outside cybersecurity experts to assess how intruders got in and what was accessed. In addition, this process helps determine which individuals need to be notified and what protections should be offered.

At this stage, the public record does not include further technical details about the breach. Still, the confirmed exposure of Social Security numbers alone makes this incident serious. This is because that single data point can enable a wide range of fraud when combined with other identifying details.

Who was affected?

The notification identifies individuals connected to Fulcrum Real Estate Services as the affected population. Because Fulcrum operates in the real estate services sector, those affected likely include clients, tenants, property owners, or employees whose information the company stored. The exact relationship between the victims and the company has not been publicly detailed.

The source filing does not include a specific number of affected individuals. Therefore, the full scope of this breach hasn’t been publicly disclosed. What is confirmed is that at least one Vermont resident was affected, since state law requires notification once any resident’s data is compromised.

Given that real estate companies often manage sensitive financial and personal records for many clients over the course of transactions, the affected group could span multiple states. Individuals should not assume they are unaffected simply because they don’t live in Vermont. Anyone who has done business with Fulcrum should stay alert for a direct notification letter.

What Information Was Potentially Exposed?

The confirmed category of exposed data in this breach is Social Security numbers. This is one of the most sensitive pieces of personal information a company can hold, since it is a key identifier used across financial, medical, and government systems.

  • Social Security numbers

Because the notification centers specifically on Social Security numbers, affected individuals face a heightened risk of identity theft. Criminals can use a stolen Social Security number to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. Unlike a password, a Social Security number cannot simply be changed after exposure.

In addition to identity theft, victims may also face risks related to synthetic identity fraud. This occurs when criminals combine a real Social Security number with fabricated personal details to create a new, fraudulent identity. As a result, victims may not notice the misuse for months or even years, making ongoing vigilance especially important.

What is the company doing?

Fulcrum Real Estate Services responded by filing the required notification with the Vermont Attorney General. This step indicates the company completed an internal review of the incident before reaching out to regulators. Filing this notice is a legal obligation designed to keep both regulators and residents informed.

Beyond the regulatory filing, the specific remediation steps Fulcrum has taken have not been detailed in the public record. Companies in similar situations often strengthen network security, reset credentials, and work with cybersecurity specialists to prevent further unauthorized access. Whether Fulcrum is offering credit monitoring or identity protection services has not been publicly disclosed.

Affected individuals should watch for a direct letter or notice from Fulcrum. This notice would typically explain what happened, confirm what specific information was involved for that person, and outline any protective services offered. If you do business with Fulcrum and haven’t received a notice yet, it may still be forthcoming.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Because Social Security numbers were exposed, affected individuals should check their credit reports regularly. You can request a free credit report from each of the three major credit bureaus through AnnualCreditReport.com. Reviewing these reports helps you spot unfamiliar accounts or inquiries early.

In addition to checking reports, consider spacing out requests from each bureau throughout the year so you get more frequent snapshots. If you notice any account you did not open, report it immediately to the credit bureau and the creditor involved. Early detection often limits the damage from identity theft.

Consider a Fraud Alert or Credit Freeze

Given that Social Security numbers are involved, placing a fraud alert or credit freeze is a strong protective step. A fraud alert requires lenders to verify your identity before opening new credit in your name. A credit freeze goes further by blocking access to your credit file entirely until you lift it.

You can request a freeze directly with each of the three credit bureaus, and it’s free to do so. Although a freeze takes a few extra steps when you need to apply for credit yourself, it offers strong protection against fraudulent accounts. For long-term protection after a Social Security number exposure, many experts consider a freeze the more effective option.

Watch for Phishing Attempts

After a breach like this, scammers often try to exploit public awareness of the incident. Be cautious of emails, texts, or phone calls claiming to be from Fulcrum or credit agencies asking for personal information. Legitimate companies will never ask you to confirm your Social Security number through email or text.

Instead of clicking links in unsolicited messages, go directly to the official website or call a verified phone number. If a message creates urgency or pressure, treat that as a warning sign. Taking a moment to verify the source can prevent a secondary scam from compounding the original breach.

Watch for Signs of Tax and Benefits Fraud

Because Social Security numbers can be used to file fraudulent tax returns, affected individuals should file their taxes as early as possible each year. This reduces the chance that a criminal can file a false return using your information first. If the IRS rejects your return as a duplicate, that’s a red flag worth investigating immediately.

Similarly, watch for unexpected notices from the Social Security Administration or unemployment benefits agencies. These could indicate someone is using your identity to claim benefits fraudulently. If you notice anything unusual, report it right away and consider consulting a data breach attorney to understand your legal options and whether you may be eligible for compensation.



More Information

Official data breach notification from Delaware Attorney General

Official data breach notification from Vermont Attorney General

Related Data Breaches

View the full list of tracked data breaches →