Castle Group: Castle Group Data Breach Investigation

Castle Group: Castle Group Data Breach Investigation

Castle Group Data Breach Exposes Sensitive Personal Information in Prolonged Cyberattack

Castle Group, a Florida-based property management firm specializing in luxury residential communities, suffered a significant data breach after an unauthorized actor infiltrated its network between September 2025 and February 2026. The company, headquartered in Plantation, Florida, provides high-end property management, financial, and lifestyle services under its "Royal Service" philosophy.

The breach was discovered on August 11, 2026, when Castle Group identified that sensitive personal data had been compromised. The company responded by securing its systems and engaging cybersecurity experts to investigate. The Qilin ransomware group later claimed responsibility, announcing on February 17, 2026, via the dark web that it had exfiltrated business and financial records.

On August 26, 2026, Castle Group formally disclosed the incident to the Massachusetts and Vermont Attorneys General. The exposed data includes Social Security numbers, government ID numbers, financial account details, credit/debit card information, and health records putting affected individuals at risk of identity theft and financial fraud.

Class action law firm Shamis & Gentile P.A. is investigating potential legal claims on behalf of those impacted, with affected parties potentially eligible for compensation. The breach highlights the growing threat of ransomware attacks targeting corporate networks and the long-term risks of prolonged unauthorized access.

Source: https://www.claimdepot.com/investigations/castle-group-data-breach-2026

The Castle Group cybersecurity rating report: https://www.rankiteo.com/company/the-castle-group

"id": "THE1788442524",
"linkid": "the-castle-group",
"type": "Ransomware",
"date": "9/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Real Estate, Property Management',
                        'location': 'Plantation, Florida, USA',
                        'name': 'Castle Group',
                        'type': 'Property Management Firm'}],
 'attack_vector': 'Unauthorized network infiltration',
 'data_breach': {'data_exfiltration': 'Yes',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Social Security numbers',
                                              'Government ID numbers',
                                              'Financial account details',
                                              'Credit/debit card information',
                                              'Health records']},
 'date_detected': '2026-08-11',
 'date_publicly_disclosed': '2026-08-26',
 'description': 'Castle Group, a Florida-based property management firm '
                'specializing in luxury residential communities, suffered a '
                'significant data breach after an unauthorized actor '
                'infiltrated its network between September 2025 and February '
                '2026. The breach exposed sensitive personal data, including '
                'Social Security numbers, government ID numbers, financial '
                'account details, credit/debit card information, and health '
                'records, putting affected individuals at risk of identity '
                'theft and financial fraud.',
 'impact': {'brand_reputation_impact': 'High',
            'data_compromised': 'Sensitive personal information, financial '
                                'records, health records',
            'identity_theft_risk': 'High',
            'legal_liabilities': 'Potential class action lawsuits',
            'payment_information_risk': 'High'},
 'initial_access_broker': {'reconnaissance_period': 'September 2025 - February '
                                                    '2026'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain, Data exfiltration',
 'ransomware': {'data_exfiltration': 'Yes', 'ransomware_strain': 'Qilin'},
 'references': [{'date_accessed': '2026-02-17',
                 'source': 'Dark web announcement by Qilin ransomware group'},
                {'date_accessed': '2026-08-26',
                 'source': 'Castle Group disclosure to Massachusetts and '
                           'Vermont Attorneys General'}],
 'regulatory_compliance': {'legal_actions': 'Potential class action '
                                            'investigation by Shamis & Gentile '
                                            'P.A.',
                           'regulatory_notifications': ['Massachusetts '
                                                        'Attorney General',
                                                        'Vermont Attorney '
                                                        'General']},
 'response': {'communication_strategy': 'Disclosure to Massachusetts and '
                                        'Vermont Attorneys General',
              'containment_measures': 'Secured systems',
              'incident_response_plan_activated': 'Yes',
              'third_party_assistance': 'Cybersecurity experts'},
 'threat_actor': 'Qilin ransomware group',
 'title': 'Castle Group Data Breach Exposes Sensitive Personal Information in '
          'Prolonged Cyberattack',
 'type': 'Data Breach, Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.