Castle Group Discloses Ransomware Attack Exposing Sensitive Personal Data
Castle Group, a Florida-based property management company overseeing residential communities nationwide, recently reported a data breach stemming from a ransomware attack. The incident, disclosed to state regulators on August 26, 2026, affected at least 38 Massachusetts residents and 5 Vermont residents, though the full scope remains unclear.
Unauthorized access to Castle Group’s network occurred between September 2025 and February 2026, with the ransomware group Qilin claiming responsibility on February 17, 2026, via a dark web post. The breach exposed a range of sensitive personal data, including names, Social Security numbers, government IDs, financial account details, and health records.
Following the discovery, Castle Group engaged external cybersecurity experts to conduct a forensic investigation, confirming the compromise of systems containing personal information. In response, the company is offering complimentary identity theft protection services through Cyberscout (a TransUnion subsidiary) to affected individuals, along with a dedicated toll-free response line for inquiries, available weekdays from 8 a.m. to 8 p.m.
The incident highlights the ongoing threat of ransomware attacks targeting organizations handling sensitive consumer data.
Source: https://www.claimdepot.com/data-breach/castle-group-2026
Castle Group cybersecurity rating report: https://www.rankiteo.com/company/castle-group
"id": "CAS1788406361",
"linkid": "castle-group",
"type": "Ransomware",
"date": "9/2025",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'At least 38 Massachusetts '
'residents and 5 Vermont '
'residents',
'industry': 'Real Estate/Property Management',
'location': 'Florida, USA',
'name': 'Castle Group',
'type': 'Property Management Company'}],
'customer_advisories': 'Complimentary identity theft protection services and '
'a dedicated toll-free response line',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Names',
'Social Security numbers',
'Government IDs',
'Financial account details',
'Health records']},
'date_detected': '2026-02-17',
'date_publicly_disclosed': '2026-08-26',
'description': 'Castle Group, a Florida-based property management company '
'overseeing residential communities nationwide, recently '
'reported a data breach stemming from a ransomware attack. The '
'incident exposed sensitive personal data, including names, '
'Social Security numbers, government IDs, financial account '
'details, and health records.',
'impact': {'data_compromised': 'Sensitive personal data including names, '
'Social Security numbers, government IDs, '
'financial account details, and health records',
'identity_theft_risk': 'High',
'payment_information_risk': 'High'},
'investigation_status': 'Ongoing',
'ransomware': {'data_exfiltration': 'Yes', 'ransomware_strain': 'Qilin'},
'references': [{'source': 'State regulatory disclosure'}],
'regulatory_compliance': {'regulatory_notifications': 'Disclosed to state '
'regulators'},
'response': {'communication_strategy': 'Offering complimentary identity theft '
'protection services through '
'Cyberscout and a dedicated toll-free '
'response line',
'third_party_assistance': 'External cybersecurity experts'},
'threat_actor': 'Qilin',
'title': 'Castle Group Discloses Ransomware Attack Exposing Sensitive '
'Personal Data',
'type': 'Ransomware'}