NAI Earle Furman, a commercial real estate firm, suffered a ransomware attack by a group called secp0 that accessed a file server containing employee, broker commission, brokerage deal, and property-management records. The exact number of affected individuals has not been disclosed. Anyone connected to the firm should monitor credit reports and watch for phishing attempts immediately.
| Company | NAI Earle Furman |
|---|---|
| Industry | Real Estate |
| Data Types Exposed | Employee Personal Files, Broker Commission Records, Brokerage Deal Documentation, Property-Management Accounting Data, Financial Account Information, Business Records from Croxton Gray |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the NAI Earle Furman Data Breach?
NAI Earle Furman, a commercial real estate firm, has confirmed a data breach tied to a ransomware attack on its internal file server. A threat actor group known as secp0 claimed responsibility for accessing and copying files from the company’s network. This breach adds NAI Earle Furman to a growing list of professional services firms hit by targeted ransomware campaigns.
According to available details, the attackers obtained a large volume of data from a single file server, identified internally as the E:/Shares directory. This tree reportedly contained more than 1.36 million file paths. As a result, the exposure appears to span multiple business functions rather than a single department.
The compromised data reportedly includes information tied to brokerage deals, property-management accounting records, and broker commission details. In addition, employee home directories were part of the exposed file structure. Data belonging to Croxton Gray, a firm previously absorbed by NAI Earle Furman, also appears within the same exposed dataset.
The breach discovery date has not been publicly disclosed. Because ransomware groups often post stolen files to leak sites well after initial access, the actual intrusion may have occurred earlier than when it became publicly known. NAI Earle Furman has not released a detailed timeline explaining when the unauthorized access first began.
Following discovery of the incident, the company presumably launched an internal investigation to determine the scope of the intrusion. However, specific forensic findings, such as the exact entry point or how long the attackers had access, have not been made public. Affected individuals should watch for official notification letters that may include more precise details.
Who was affected?
The breach may affect several distinct groups connected to NAI Earle Furman’s operations. Because the exposed file server included employee home directories, current and former staff members could be impacted. Their personal files, potentially including sensitive personnel information, may have been part of the stolen dataset.
In addition, the data appears to include broker commission records. This suggests that brokers affiliated with the firm may also be affected. Since the company handles brokerage deals and property management, clients, tenants, or property owners tied to those portfolios could be impacted as well.
The inclusion of Croxton Gray’s data means individuals connected to that previously absorbed firm may also be part of the affected population. This expands the potential scope beyond NAI Earle Furman’s current client and employee base. The exact number of individuals affected has not been publicly disclosed.
Because the breach involves a US-based commercial real estate firm, the affected population is likely concentrated within the regions where NAI Earle Furman and Croxton Gray conducted business. Minors are unlikely to be directly involved, though this cannot be fully ruled out given the presence of employee personal files.
What Information Was Potentially Exposed?
The exposed file server reportedly contained a wide variety of business and personal records. While the company has not issued a full itemized list, the nature of the files suggests several categories of sensitive information were accessible to the attackers.
- Employee personal files from home directories
- Broker commission and compensation records
- Brokerage deal documentation
- Property-management accounting data (MRI system records)
- Business records absorbed from Croxton Gray
- Potential financial account or payment information tied to transactions
Given the presence of commission and accounting data, financial information may be at risk. This creates a realistic possibility of fraud attempts targeting brokers or property owners named in these records. Attackers could use transaction details to craft convincing scams or attempt unauthorized fund transfers.
Furthermore, employee home directories often contain a mix of personal identifiers. This could include documents referencing Social Security numbers, banking details, or other identity-related information. If such data was included, affected employees could face a heightened risk of identity theft.
Because property-management data was involved, tenants or property owners connected to managed portfolios could also see exposure of lease, payment, or account information. This type of exposure can lead to targeted phishing attempts that reference real account details, making scams harder to detect.
What is the company doing?
In response to the breach, NAI Earle Furman likely engaged cybersecurity specialists to assess the extent of the intrusion. Companies facing similar ransomware incidents typically work to contain the threat, secure remaining systems, and determine which files were accessed or copied.
As part of standard breach response, the firm may also be coordinating with legal counsel to meet notification obligations. Affected individuals should expect written notice if their personal information was confirmed to be part of the stolen data. At this time, NAI Earle Furman has not publicly detailed specific remediation steps or protective services being offered.
Because breach investigations often continue for weeks or months, additional findings may emerge over time. Individuals connected to the firm should monitor official communications closely. This includes checking for updates from NAI Earle Furman regarding the scope of the incident and any support services made available.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should request a copy of their credit report from each of the three major credit bureaus. Reviewing these reports carefully can help identify unfamiliar accounts or inquiries. Early detection is one of the most effective ways to limit damage from identity theft.
In addition, consumers can access free weekly credit reports through AnnualCreditReport.com. Because ransomware breaches sometimes lead to delayed misuse of data, ongoing monitoring over the coming months is important. Setting a recurring reminder to check your reports can help maintain consistent oversight.
Consider a Fraud Alert or Credit Freeze
Given that financial and commission-related records may have been exposed, placing a fraud alert on your credit file is a reasonable precaution. A fraud alert requires lenders to take extra steps to verify your identity before extending credit. This can slow down or stop fraudulent applications made in your name.
For stronger protection, individuals can also request a credit freeze with each bureau. This restricts access to your credit file entirely until you lift the freeze. Because commission and financial data appear to be part of the breach, this added layer of security may be worthwhile for brokers and employees alike.
Watch for Phishing and Social Engineering Attempts
Attackers who obtain business and personal records often use that information to craft convincing phishing emails or phone calls. As a result, affected individuals should be cautious of unexpected messages referencing real transaction or employment details. Scammers may pose as NAI Earle Furman, a bank, or a government agency.
Before clicking any links or sharing information, verify the sender through a separate, trusted communication channel. This means calling a known phone number rather than one provided in the suspicious message. Because leaked data can lend false credibility to scams, extra caution is essential in the months following a breach.
Review Financial and Business Accounts Regularly
Brokers and employees whose commission or payment information may have been exposed should review related financial accounts frequently. This includes checking bank statements, payment processors, and any accounts tied to commission disbursements. Look for unauthorized transactions or unfamiliar changes to account details.
If anything appears suspicious, contact your financial institution immediately. Reporting unauthorized activity quickly can limit financial losses. Individuals who are unsure about their legal options after this breach may also benefit from speaking with a data breach attorney for a free case evaluation.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
