Marcus & Millichap Data Breach (2026): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Marcus & Millichap disclosed a data breach on April 12, 2026, affecting 1.8 million individuals whose email addresses, employers, job titles, names, and phone numbers were exposed. Anyone who has shared personal details with the firm should review their accounts and consider protective steps such as changing passwords or enabling two-factor authentication.
What happened
On 12 April 2026, Marcus & Millichap was named in connection with a claimed intrusion by ShinyHunters. The group listed the firm among multiple alleged victims and released a dataset said to contain 1.8 million unique email addresses together with names, phone numbers, employers, job titles and physical company addresses. Marcus & Millichap’s notice described the potentially accessed material as limited to company forms, templates, marketing materials and general information. No further details on the method of access, exact timing of the intrusion or confirmation of the dataset’s origin have been made public.
Inside shinyhunters
ShinyHunters is a publicly documented threat actor known for obtaining corporate data through unauthorized access and then listing organizations on public leak sites. The group has previously claimed responsibility for incidents involving customer or employee records from various sectors. In this case the group claims Marcus & Millichap data was obtained and released; that claim remains unverified by independent confirmation in available reporting.
Marcus & Millichap and its sector
Marcus & Millichap operates as a commercial real estate brokerage, facilitating property transactions and maintaining contact information for clients, brokers and partner organizations. Firms in this sector routinely collect names, professional titles, email addresses, telephone numbers and physical business addresses to support deal coordination and marketing. A dataset of this nature can therefore contain details that identify individuals across multiple organizations and locations.
What was likely exposed
The publicly posted records are reported to include the following categories of information:
- Email addresses
- Names
- Phone numbers
- Employers
- Job titles
- Physical addresses
Marcus & Millichap’s disclosure characterized any accessed material as limited to internal forms, templates and marketing content. The precise overlap between the posted dataset and the company’s description remains unconfirmed.
What's at stake
Individuals whose records appear in the dataset may receive unsolicited messages or be targeted in phishing attempts that reference their employer or job function. Organizations that rely on accurate contact data for business dealings face the possibility of increased spam or social-engineering activity directed at staff. No confirmed instances of subsequent misuse have been documented in available reports.
What to do if you're exposed
Recipients of unexpected messages referencing the firm or their listed details should verify the sender through independent channels before responding. Enabling multi-factor authentication on any associated accounts and reviewing privacy settings on professional profiles can reduce further exposure. Readers can run a free exposure scan of their email to check whether their information has surfaced in known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Kemper Data Breach (2026)Abrigo Data Breach (2026)Sysco Data Breach (2026)American Tower Data Breach (2026)Latest breaches
Read GalaxyWarden’s full analysis of the Marcus & Millichap Data Breach (2026) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.