[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f23tftttyuv92o":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":13,"affectedCountUnit":23,"hasEnglishDescription":4,"contentLocale":24,"availableLocales":25,"translations":27,"severity":30,"dataClasses":31,"description":37,"seoTitle":38,"seoDescription":39,"logoUrl":40,"isVerified":4,"isSensitive":41,"isSpamList":41,"isMalware":41,"company":42},"6a452308a20f867c8ba8e77a","Berkadia","Berkadia Data Breach","berkadia","berkadia.com","2026-03-19T00:00:00.000Z","2026-06-15T04:09:04.000Z",null,"2026-07-02T04:54:07.310Z","2026-07-19T00:03:31.820Z","Commercial real estate contact data breach","https:\u002F\u002Fwww.berkadia.com\u002F",[17,19,20],"https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fberkadia-2026","https:\u002F\u002Fwww.breachsense.com\u002Fbreaches\u002Fberkadia-data-breach\u002F",305216,"known","unknown","en",[24,26],"tr",{"en":28,"tr":29},{"slug":9},{"slug":9},"High",[32,33,34,35,36],"Email addresses","Employers","Names","Phone numbers","Physical addresses","\u003Cp>The Berkadia data breach is an incident recorded on March 19, 2026, involving the publication of corporate communication data related to commercial real estate financing and consulting services. The verified searchable scope of this record is 305,216 unique email addresses. The verified data categories are email addresses, employer information, names, phone numbers, and physical addresses.\u003C\u002Fp>\n\u003Cp>This record does not claim that passwords, bank accounts, credit files, investment amounts, tax information, official identification documents, or complete transaction records have been leaked. The main source of risk is that, in the context of real estate financing and commercial transactions, it makes messages such as fake document sharing, payment routing, financing offers, contract updates, or representative communication more convincing.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified data types are email addresses, employers, names, phone numbers, and physical addresses. Although these fields do not directly contain financial account data, they are valuable for targeted social engineering in business contexts. When a person's associated company, name, phone number, and address are known, fake financing or document messages can appear more personal.\u003C\u002Fp>\n\u003Cp>In commercial real estate financing processes, since document, payment, e-signature, consulting, and contract communication are common, attackers may exploit these themes. Even if the verified dataset does not include a credit file or bank account, the contact information can provide enough context to act as if there is an ongoing transaction. Therefore, the risk is more about business email fraud and document routing attempts rather than direct account takeover.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified event date is March 19, 2026, and the verified searchable scope is 305,216 unique email addresses. This number does not mean that all rows represent separate individuals. In corporate customer and business development systems, the same person can be associated with multiple companies, opportunities, transactions, or communication records. Therefore, the number of rows, business records, and unique email addresses should be kept separate.\u003C\u002Fp>\n\u003Cp>This record does not claim that payment card, bank account, credit application file, investment amount, tax record, password, account session, or official identification document has been leaked. Verified scope is limited to contact and employer fields. The risk is that fraudulent payment, document, and representative communication could be established using the context of commercial real estate financing.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Individuals who have contacted Berkadia in the context of business development, financing, consulting, investment sales, credit, or commercial real estate transactions may be at risk. Employer information helps the attacker personalize the message according to the company or transaction role. Phone and physical address fields indicate that targeting can also be done through channels other than email.\u003C\u002Fp>\n\u003Cp>Real estate investors, brokers, finance teams, legal and contract teams, executive assistants, and those involved in commercial property transactions should be especially careful. Fake financing offers, document uploads, e-signatures, bank account changes, closing payments, or representative change messages may resemble real transaction flows. Such requests should not be confirmed with a single email or phone call.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users in the matching area must ensure that they use strong and unique passwords for their work email accounts, that two-step verification is enabled, and that there are no suspicious sessions. Passwords are not a verified data class in this incident; however, attempts to collect passwords may occur through a fake document sharing portal or a funding file link. File sharing and e-signature requests must be verified through a known representative.\u003C\u002Fp>\n\u003Cp>Messages regarding bank account changes, payment routing, closure instructions, contract updates, or urgent document uploads must be confirmed through a secondary channel. Even if the caller provides the actual company name, address, or transaction context during phone calls, information should not be shared. Finance and legal teams should use multi-step approval for high-value transactions.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Communication data alone carries high value in commercial real estate and financing processes. Institutions should regularly review records of prospective clients, investors, brokers, and transaction contacts; clean up unnecessary old records; and restrict access permissions in business communication systems. High-value payment and document processes should not rely on a single communication channel.\u003C\u002Fp>\n\u003Cp>On the user side, business email security, unique passwords, two-factor authentication, and careful verification of document sharing links are fundamental protections. In real estate transactions, payment instructions, changes of representative, and document requests should always be confirmed through an independent channel. This incident shows that the context of a financial transaction can provide enough assurance for fraud even without a financial data leak.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match with the email address in this record indicates that the address is included in Berkadia's corporate communications or business development dataset. A match does not mean that the credit file, password, or bank account has been compromised. The user should first identify which company, transaction, consulting, or real estate financing process they used this email address for.\u003C\u002Fp>\n\u003Cp>The correct action is to secure the work email account, verify document and payment requests through an independent channel, approach urgent requests received by phone with caution, and request a second approval for high-value transaction communications. A message containing the real employer or address information is not proof of reliability; the request must be confirmed through a known representative or official channel before any transaction is made.\u003C\u002Fp>","Berkadia Data Breach (305.2 Thousand Reported Records)","Berkadia Data Breach. 305.2 Thousand reported records are reported. Reported data: Email addresses, Employers, Names. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fberkadia_com.webp",false,{"name":7,"sector":43,"country":44,"website":10,"websiteArchiveUrl":45,"websiteStatus":45,"websiteCheckedAt":13},"Real Estate","United States",""]