What Happened in the New Hampshire Housing Data Breach?
New Hampshire Housing has disclosed a data security incident tied to its Yardi RentCafe software portal. The agency, which runs the Housing Choice Voucher program connecting landlords and tenants statewide, learned that a participating landlord’s personal email account had been compromised. As a result, an unauthorized party gained entry into that landlord’s account within the RentCafe portal.
According to the notification filed with the New Hampshire Attorney General’s Office, the unauthorized access to the landlord’s portal occurred in July 2026. Once inside, the intruder altered the landlord’s banking details on file. This change allowed the attacker to redirect $848 in HUD subsidy funds away from the intended recipient.
New Hampshire Housing says the incident traces back to the landlord’s own email account rather than a flaw in its internal systems. In other words, the agency’s core network and the RentCafe platform itself were not directly breached. Because of this, the agency has framed the event as an isolated account-takeover incident rather than a widespread system failure.
New Hampshire Housing reported the matter to the state Attorney General’s Office in late July 2026. The agency also alerted the U.S. Department of Housing and Urban Development, since federal subsidy funds were involved. This dual notification suggests the agency is treating the incident seriously, even though it says the exposure was limited to one landlord’s portal data.
Who was affected?
The breach primarily affected one landlord participating in the Housing Choice Voucher program, along with the tenants connected to that landlord’s rental units. New Hampshire Housing has not publicly disclosed a specific number of individuals affected. However, because tenant ledgers and landlord contact records were stored together in the same portal profile, several people connected to that account could have had their information exposed.
Because the Housing Choice Voucher program serves lower-income renters, this incident could disproportionately affect households already navigating housing assistance. Tenants may not have been directly notified if their landlord was the one whose account was compromised. As a result, some tenants might be unaware their names, addresses, and payment histories were potentially viewable by an unauthorized user.
What Information Was Potentially Exposed?
The exposed data varies depending on whether an individual was a tenant or a landlord tied to the compromised account. New Hampshire Housing indicated the following categories of information were accessible to the unauthorized user through the landlord’s portal profile.
- Tenant names and addresses
- A ledger of rental payment history
- Landlord banking information, including bank name, routing number, account number, and account type
- Landlord name, mailing address, phone numbers, and email address
- Landlord Tax ID number, which may be an Employer Identification Number or a Social Security number
This combination of data creates real risk, particularly for the affected landlord. Because banking details and a Tax ID number were both accessible, criminals could attempt to open fraudulent accounts or redirect further payments. Financial fraud is the most immediate concern given that the attacker already succeeded in diverting subsidy funds once.
Tenants face a different, though still meaningful, risk. Names, addresses, and payment ledgers alone are less useful for direct financial fraud. However, this information could still support convincing phishing attempts, especially if combined with other data attackers may already hold from unrelated sources.
What is the company doing?
New Hampshire Housing responded by notifying both state and federal authorities after learning of the compromise. The agency filed a formal notification with the New Hampshire Attorney General’s Office and separately informed HUD, given the misuse of federal subsidy funds. This coordinated notification shows the agency treated the fund diversion as a reportable incident requiring outside oversight.
In addition, the agency stated it is reviewing additional verification steps for any future changes to banking or payment information within the portal. This suggests New Hampshire Housing recognizes the need for stronger controls before account details can be altered. Meanwhile, the agency emphasized that the breach did not stem from a flaw in the Yardi RentCafe platform itself, distinguishing this incident from a broader software vulnerability.
What Should Affected Individuals Do?
Monitor Bank and Payment Accounts Closely
Anyone connected to the affected landlord account, especially the landlord themselves, should review recent bank and payment statements right away. Look for unauthorized withdrawals, unfamiliar transfers, or changes to account details you did not authorize.
Because the attacker already succeeded in rerouting subsidy funds once, similar attempts could follow. If you notice anything suspicious, report it to your financial institution immediately and ask about additional fraud protections on your account.
Consider a Credit Freeze or Fraud Alert
Because a Tax ID number, which may be a Social Security number, was potentially exposed, affected landlords should consider placing a fraud alert or credit freeze with the major credit bureaus. This makes it harder for anyone to open new credit accounts using your information.
A credit freeze is free and can be lifted temporarily whenever you need to apply for credit yourself. This step is one of the strongest protections available when a Social Security number may have been exposed.
Monitor Your Credit Reports Regularly
All affected individuals, whether tenants or landlords, should check their credit reports for unfamiliar accounts or inquiries. You can access free reports at annualcreditreport.com from each of the three major bureaus.
Reviewing these reports regularly helps you catch fraudulent activity early. As a result, you can dispute unauthorized accounts before they cause lasting damage to your credit history.
Stay Alert to Phishing Attempts
Because this breach involved a housing assistance program, scammers may send fake messages referencing rental payments, HUD subsidies, or landlord portal accounts. Be cautious of any unexpected emails or calls asking you to verify banking details or click a link.
Instead, contact New Hampshire Housing directly through a verified phone number or website if you receive a suspicious message. Enabling multi-factor authentication on your email and portal accounts also adds an extra layer of protection against similar account takeovers.
Report Suspicious Activity Promptly
If you notice anything unusual related to your housing assistance account or banking information, report it to New Hampshire Housing and your bank without delay. Quick reporting can limit further financial loss and help the agency track the scope of the incident.
You may also want to speak with a data breach attorney to understand your options. An attorney can help you evaluate whether you qualify for compensation related to this incident.
