[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2jjtu8pcjytg9":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda48825159","condo-com","Condo.com Data Breach","condocom","condo.com","2019-06-01T00:00:00.000Z","2024-07-25T04:12:07.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:48:13.765Z","Third party breach","https:\u002F\u002Fwww.hookphish.com\u002Fblog\u002Fcritical-alert-recent-condo-com-data-breach\u002F",[16],1481555,"known",null,"unknown","Critical",[24,25,26,27],"Email addresses","Names","Phone numbers","Physical addresses","\u003Cp>The Condo.com data breach is an incident associated with the exposure of user data belonging to the Condo.com service, which is related to real estate and housing listings, in June 2019. The number of confirmed affected accounts for this record is 1,481,555. The confirmed data classes are email addresses, names, phone numbers, and in a small number of records, physical addresses. The incident poses a risk of targeted fraud primarily through contact and real estate interest rather than passwords.\u003C\u002Fp>\n\u003Cp>Information found on housing search and real estate-focused services like Condo.com may lead to inferences about the user's moving, purchasing, renting, investing, or regional interests. While email, name, and phone number alone are commonly seen fields, when combined with real estate context, they can set the stage for more convincing scenarios such as fake listings, fake agents, fake loan offers, moving services, or deposit scams. The small number of records containing a physical address, on the other hand, carry a more direct personal security and privacy risk.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The verified data types are email addresses, names, phone numbers, and physical addresses. An email address can be used to match with the user's other online accounts. Names and phone numbers become valuable for fake customer service calls, listing verification messages, people pretending to be real estate agents, or payment redirection attempts. For records with a physical address, more direct information about the location where the user lives or is interested in can be obtained.\u003C\u002Fp>\n\u003Cp>This record is not a password-verified data class; therefore, the focus of the risk is phishing, phone scams, and real estate-themed social engineering rather than account passwords. The combination of name, email, and phone provides sufficient points of contact to reach a person. If an attacker assumes that the user is interested in searching for a home, renting, buying, or an apartment, they can customize messages according to this context. Such customization may have a higher persuasive power compared to general advertising or mass phishing messages.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>This record covers 1,481,555 affected accounts and the incident date is recorded as June 1, 2019. It is understood that the data later resurfaced in circulation within a larger breach compilation. This means that, even though the incident is dated, the email and phone information could be reused in current fraud lists. The record coverage should be evaluated based on the number of unique accounts; it should not be assumed that each row represents a current, active, or complete user profile.\u003C\u002Fp>\n\u003Cp>The verified fields are email address, name, phone number, and a small number of physical addresses. In this record, password, payment card, bank account, social security number, date of birth, ID document, or real estate transaction document are not verified data types. Additionally, the physical address field is seen not in all records, but in a small portion. This distinction is important; when explaining the actual risk to the user, it is necessary both not to underestimate the value of communication data and not to present unverified data types as if they exist.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The individuals at the highest risk are those who have used their real name, primary email address, and active phone number on Condo.com. Users in the real estate search process are generally concerned with high-value decisions such as moving, investing, renting, or buying. Therefore, attackers may target users with themes such as fake consulting, fake listings, deposit redirection, credit pre-approval, appraisal fees, maintenance fee notifications, or moving services.\u003C\u002Fp>\n\u003Cp>For users who also have a physical address, the risk becomes more personalized. If the address information is accurate, the attacker can try to build trust in the message by using elements such as neighborhood, building, delivery, maintenance, subscription, or management announcements. Users with a phone number can be directly targeted via text messages and calls. For those registered with a work email, there is also a risk of corporate phishing; because messages themed around real estate and facility management may appear reasonable in a work environment.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>In this record, the user who sees a match should primarily be cautious about real estate-themed messages coming via email and phone. Unexpected listing offers, deposit requests, quick payment instructions, loan application links, rental agreement files, or account verification messages should not be directly considered trustworthy. If a real estate transaction is to be made, the party's identity, the source of the listing, payment information, and communication channel should be verified independently.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication should be enabled on the email account and suspicious sessions should be checked. Even if the record does not have a password-verified field, the email account can be a central target for fraud messages. One-time codes sent to the phone number, identity document requests, deposit payment instructions, or remote access requests should not be shared. Users whose physical address may have been leaked should also consider messages arriving under the pretense of address verification or delivery as suspicious.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Condo.com incident shows that contact information can have serious security and privacy implications, even if it does not include a password. Users should use separate email addresses or masking solutions whenever possible for real estate, listings, subscriptions, and shopping services. Sharing a phone number should not be done unless mandatory; if it is mandatory, one should be aware of potential marketing, scam, and phishing messages in the future. A physical address should only be shared for transactions where it is truly necessary.\u003C\u002Fp>\n\u003Cp>In the long term, users should review old real estate accounts and listing profiles. Unused accounts should be closed, public profile information should be reduced, and it should be monitored which services have been registered with the same contact information. Since real estate transactions carry high financial value, payment steps should never be carried out solely according to instructions received via email or text message. The other party's license, listing ownership, bank information, and contract details should be verified through separate channels.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The presence of a match in this record indicates that the relevant email address is among the records associated with the Condo.com leak. The match shows that the verified scope is limited to contact and identity information; password or payment information is not included among the verified data classes of this record. However, when email, name, and phone number are combined, there may be enough data to generate messages that appear personalized to the user. Therefore, caution is required even if the record is old.\u003C\u002Fp>\n\u003Cp>The user should first secure their email account, verify unexpected messages related to real estate and moving through a separate channel, and refuse payment or identity requests received by phone. Users who think their physical address may be known should carefully examine messages related to delivery, maintenance, building management, or subscriptions. In real estate transactions, listings, individuals, companies, and account information should be verified through independent sources before any money is transferred.\u003C\u002Fp>","","Condo.com Data Breach (1.5 Million Reported Records)","Condo.com Data Breach. 1.5 Million reported records were reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fcondo_com.webp",false,{"name":35,"sector":36,"country":37,"website":10,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":20},"Condo.com","Real estate marketplace","United States"]