Berkadia Data Breach (2026): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Berkadia disclosed a data breach on March 19, 2026, that exposed the email addresses, employers, names, phone numbers, and physical addresses of 305,000 individuals. Anyone who may have been a client or had dealings with the firm should review the official notice and consider protective steps.
In March 2026, records associated with approximately 305,000 individuals connected to Berkadia appeared in public claims following an extortion campaign against the commercial real estate finance company. The incident involved data reportedly drawn from the firm’s Salesforce environment and included email addresses along with names, physical addresses, phone numbers, and employer details. For the people whose information was listed, the exposure raises straightforward questions about how that data might be used in unsolicited contacts or combined with other records already circulating online.
Breaking down the breach
The matter came to wider attention on 19 March 2026, when an external group stated it had obtained material from Berkadia and published a portion of the claimed records after an unsuccessful extortion demand. The published material was described as originating from the company’s Salesforce instance and was said to contain more than 300,000 unique email addresses together with associated names, physical addresses, phone numbers, and employer information. Public reporting at the time did not include an official statement from Berkadia confirming the source or the precise volume of records involved, and no independent forensic assessment has been released.
How a breach like this happens
Incidents involving cloud-hosted customer-relationship platforms often begin with credential access obtained through phishing, password reuse, or misconfigured permissions. Once inside, an actor can export contact and account records that are routinely stored in such systems. In extortion campaigns, the operators first contact the target organization with a demand for payment and, if unsuccessful, release samples or larger datasets on public forums to pressure the victim or to monetize the information directly. The technical path does not require sophisticated custom malware; it frequently relies on valid credentials or overly broad access rights that allow bulk data extraction.
Who is Berkadia?
Berkadia operates as a commercial real estate finance and investment services firm. Organizations of this type maintain extensive records on borrowers, property owners, brokers, and service providers in order to underwrite loans, manage portfolios, and coordinate transactions. These records commonly include contact information that can remain in active use for years after a single financing event, creating a long-lived dataset that spans multiple parties connected to the same property or loan.
What data was at risk
The published claims listed email addresses, names, physical addresses, phone numbers, and employer names. Organizations in commercial real estate finance routinely hold additional fields such as loan identifiers, property details, and financial contact points, yet it remains unconfirmed whether those fields were included in the released material. The exact scope of records that left the environment has not been verified through an official disclosure, so the full set of exposed attributes is not publicly established.
Why it matters
Individuals whose contact details appear in such datasets can expect an increase in unsolicited messages and telephone calls, some of which may attempt to impersonate legitimate financial or real-estate entities. When names and addresses are paired with employer information, the records become more useful for targeted social-engineering attempts. For the organization, the incident adds to the body of evidence that customer and partner data held in cloud platforms require strict access controls and monitoring, regardless of the sector’s regulatory baseline.
If your data was in this breach
Begin by treating any unexpected email or call referencing a real-estate or financing matter with extra caution and verify the sender through independent channels. Review account statements and credit reports for unusual activity, and consider placing a credit freeze if you have no immediate need for new credit lines. You can also run a free exposure scan of your email address against known breach datasets to see whether your information appears in other publicly discussed incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Moody Bible Institute Data Breach (2026)Sysco Data Breach (2026)JCPenney Data Breach (2026)American Tower Data Breach (2026)Latest breaches
Read GalaxyWarden’s full analysis of the Berkadia Data Breach (2026) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.