Marcus & Millichap Breach: ShinyHunters Leaks 1.8M Records

Marcus & Millichap Breach: ShinyHunters Leaks 1.8M Records

Commercial real estate giant Marcus & Millichap was publicly named in April 2026 as an alleged victim of the ShinyHunters hacking and extortion group. Have I Been Pwned reports that data purportedly obtained from the company was subsequently dumped, exposing 1.8 million unique email addresses. This isn’t just email; the leak includes names, phone numbers, employer details, job titles, and physical company addresses.

Marcus & Millichap’s disclosure notice downplayed the impact, suggesting accessed data was limited to “company forms, templates, marketing materials, and general contact information.” This is a classic move to manage optics, but the reality is far more concerning. Names, employers, job titles, and physical addresses are prime fodder for spear-phishing and social engineering attacks, especially against high-value targets in the real estate sector. Attackers now have a detailed blueprint to craft highly convincing lures.

ShinyHunters continues to hit organizations across various sectors, proving their capability to exfiltrate significant volumes of data. This incident underscores the critical need for robust data segmentation and strict access controls, even for what seems like “general contact information.” Attackers are always looking for the dots to connect, and this type of data provides a lot of them.

What This Means For You

  • If your organization has employees or partners who interact with Marcus & Millichap, assume their contact details are compromised. Alert your teams to heightened spear-phishing risks. Review your email gateway rules for unusual activity and ensure multi-factor authentication is enforced across all critical services to mitigate credential stuffing attempts.

🛡️ Detection Rules

3 rules · 6 SIEM formats

3 detection rules auto-generated for this incident, mapped to MITRE ATT&CK. Sigma YAML is free — export to any SIEM format via the Intel Bot.

critical T1048 Exfiltration

Marcus & Millichap Data Exfiltration via ShinyHunters

Sigma YAML — free preview

Source: Shimi's Cyber World · License & reuse

✓ Sigma · Splunk SPL Sentinel KQL Elastic QRadar AQL Wazuh Get rules for your SIEM →
Take action on this incident
📡 Monitor marcusmillichap.com Free · 1 watchlist slot · instant alerts on new breaches 🔍 Threat intel on Marcus & Millichap All breaches, IOCs & vendor exposure

Related coverage on Marcus & Millichap

ZenBusiness Breach: ShinyHunters Exfiltrates 5M Records from Snowflake, Mixpanel, Salesforce

In March 2026, the hacker and extortion group ShinyHunters claimed a significant data exfiltration from ZenBusiness, a business formation and compliance platform. The group asserted...

data-breachransomwaretools
/SCW Research /HIGH /⚙ 3 Sigma

Scattered Spider Arrest, OFAC Hits Iran Crypto, NSA Tool Vulnerability

SecurityWeek reports several critical developments that defenders should track. The arrest of a Scattered Spider hacker is a significant win, but this group remains a...

threat-intelvulnerabilitydata-breachmicrosofttools
/SCW Vulnerability Desk /HIGH /⚑ 1 IOC

Microsoft Windows 11 KB5083631 Update: 34 Changes and Fixes

Microsoft has rolled out the optional cumulative update KB5083631 for Windows 11, delivering 34 changes and fixes. BleepingComputer reports that the update includes a new...

threat-inteldata-breachmalwaremicrosofttools
/SCW Research /MEDIUM