Greystar Real Estate Partners Data Breach Exposes Social Security Numbers and Personal Information

Published: 18 September 2026
Real Estate data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: 5th November 2021

Greystar Real Estate Partners, LLC disclosed a data breach involving unauthorized access to personal information, including Social Security numbers, affecting individuals connected to its real estate operations. The exact number affected hasn’t been publicly disclosed. Affected individuals should immediately place a credit freeze or fraud alert and monitor their credit reports closely for signs of identity theft.

CompanyGreystar Real Estate Partners, LLC
IndustryReal Estate
Data Types ExposedFull Names, Social Security Numbers, Financial Account Information, Contact Information, Other Personally Identifying Information
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedDelaware Attorney General, Vermont Attorney General, Washington State Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Greystar Real Estate Partners Data Breach?

Greystar Real Estate Partners, LLC has confirmed that unauthorized parties gained access to sensitive personal information belonging to individuals connected to its operations. The company filed formal breach notifications with multiple state regulators, including the Washington State Attorney General. This filing confirmed that a data security incident had occurred and that personal information was compromised.

The exact discovery date has not been publicly disclosed. However, because Greystar filed notifications with the Delaware Attorney General in 2021 and later with the Vermont and Washington Attorneys General in 2026, the incident appears to have required an extended investigation before individuals could be notified. This gap is common in breaches involving forensic review, especially when determining exactly whose data was affected takes time.

As a result of the discovery, Greystar reportedly launched an internal investigation to determine the scope and nature of the unauthorized access. Details about the specific attack method, such as whether it involved ransomware, phishing, or another form of unauthorized network access, have not been publicly disclosed. Nonetheless, the filings confirm that personal information was accessed by someone without permission, which is the central concern for affected individuals.

Who was affected?

The breach may affect current or former residents, applicants, employees, or other individuals whose personal information was stored within Greystar’s systems. Because Greystar operates as a large real estate management company, its systems likely contain records tied to leasing, employment, and property management activities across many states.

The exact number of affected individuals has not been publicly disclosed. In addition, the specific geographic scope of the breach has not been detailed in the available filings. However, because notifications were sent to attorneys general in Delaware, Vermont, and Washington, the breach likely affected residents across multiple states rather than a single region.

It also remains unclear whether minors were among those affected. Individuals who applied for housing, worked for Greystar, or had any relationship involving personal data submission should consider themselves potentially impacted until they receive official confirmation.

What Information Was Potentially Exposed?

While the precise scope of exposed data has not been fully detailed in public filings, breach notifications of this type typically involve categories of sensitive personal information. Based on the nature of the filings and the kind of information real estate companies typically store, the following categories may have been involved.

  • Full names
  • Social Security numbers
  • Financial account information
  • Contact information such as addresses or phone numbers
  • Other personally identifying details collected during leasing or employment processes

If Social Security numbers were indeed exposed, affected individuals face a heightened risk of identity theft. Criminals can use this information to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. This type of fraud can take months to detect and even longer to fully resolve.

Additionally, exposed contact and financial details can be used in targeted phishing schemes. Scammers often pose as trusted companies to trick victims into revealing further sensitive information. Because the stolen data may already include real personal details, these scam attempts can appear highly convincing.

What is the company doing?

In response to the discovery, Greystar took steps to investigate the incident and notify affected individuals as required by law. The company filed official notifications with state regulators, confirming that it took the incident seriously and followed legal disclosure obligations.

Specifically, Greystar filed notifications with the Delaware Attorney General, the Vermont Attorney General, and the Washington State Attorney General. These filings represent the company’s ongoing compliance with state breach notification laws. As a result, affected individuals in these states should expect official written notice describing the incident and any protective services offered.

Beyond regulatory filings, further remediation steps such as system hardening or enhanced monitoring have not been publicly detailed. Individuals should watch for a formal notification letter, which typically outlines whether credit monitoring or identity protection services are being offered.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should regularly check their credit reports for unfamiliar activity. This is one of the most reliable ways to catch identity theft early, before significant damage occurs.

You can request free credit reports from all three major bureaus through AnnualCreditReport.com. Because fraud can appear months after a breach, it’s wise to check your reports periodically rather than just once.

Consider a Credit Freeze or Fraud Alert

Because Social Security numbers may have been exposed, placing a credit freeze is a strong protective step. A freeze prevents new creditors from accessing your credit file, which makes it much harder for criminals to open accounts in your name.

Alternatively, a fraud alert requires businesses to verify your identity before extending credit. This option is easier to set up and still provides meaningful protection. You can request either option directly through Equifax, Experian, or TransUnion.

Watch for Phishing Attempts

Because your contact information may have been exposed, be cautious of unexpected emails, texts, or calls claiming to be from Greystar or related services. Scammers often use breach news to create convincing but fake messages.

Never click links or share personal details in response to unsolicited messages. Instead, contact companies directly using verified phone numbers or official websites to confirm any communication.

Report Suspicious Activity Immediately

If you notice unfamiliar accounts, charges, or inquiries on your credit report, report them right away. Prompt action can limit financial damage and make recovery easier.

You can file a report with the Federal Trade Commission at IdentityTheft.gov. In addition, consider speaking with a data breach attorney to understand whether you may be entitled to compensation for damages caused by the exposure.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

Official data breach notification report (PDF) from Delaware Attorney General

View the public data breach notification listing from Vermont Attorney General

Official data breach notification report (PDF) from Washington State Attorney General

Related Data Breaches

Browse all recent data breaches →