Lincoln Property Company Commercial LLC is a Dallas-based commercial real estate operator that says it manages more than 720 million square feet across the United States and Europe. The firm has started notifying people that their personal information was exposed in a cybersecurity incident it detected on March 24, 2026. Notification letters went out on October 1, 2026, more than six months after detection. Breach-tracking sites citing state attorney general filings report that the exposed data includes Social Security numbers, tax return information, wage data and direct deposit account details. Reported victim counts differ. One tracker puts the total at about 6,585 people across Massachusetts, Texas and California. Another says that 6,585 is the Texas count alone and lists a further 540 Massachusetts residents. One breach tracker also reports that the INC Ransom group claimed the attack in early April and said it had stolen 800 GB of data. None of the sources available for this brief is a primary disclosure or an established security outlet. Every claim below is attributed to its source.
What Happened
Pieced together from the available sources, the timeline runs as follows:
- March 24, 2026: Lincoln detects the cybersecurity incident. Claim Depot and Class Action U both cite this date from the company's consumer notice. According to that notice, Lincoln brought in third-party cybersecurity experts, took steps to investigate and contain the incident, and notified law enforcement.
- April 1, 2026: Claim Depot reports that INC Ransom posted a claim against Lincoln Property Company on its Tor leak site. No other source in this set independently confirms the posting, and the company's notice, as quoted in these sources, does not name a threat actor.
- September 3, 2026: Lincoln determines that personal information belonging to specific individuals was affected (Claim Depot, Class Action U).
- October 1, 2026: Notification letters start going out. Claim Depot reports filings with the California Attorney General and the Massachusetts Office of Consumer Affairs and Business Regulation on the same day. Class Action U says the notice dated October 1 was filed with the Massachusetts Attorney General's office.
- October 2, 2026: Filing with the Texas Attorney General (Claim Depot, DataBreachCaseFile, Data Breach Legal Team).
Only Claim Depot describes the incident as a ransomware attack. The other trackers describe it more generally as a "cybersecurity incident" or "data security incident." Accounts of its current status also differ. Claim Depot and Class Action U say the company reports the incident as contained. DataBreachCaseFile says the company describes the investigation as ongoing.
Lincoln published a press release on October 1, 2026, the same day notification letters began, about advising a high-net-worth family office on three 1031 exchange acquisitions. The release does not mention the incident. The Vermont Attorney General's public breach list, as captured in the source set, has no Lincoln entry, and Vermont notes that resident counts on its list may rise as companies finish their reviews.
What Was Taken
Reported victim counts conflict:
- Class Action U: "about 6,585 people" in total, covering residents of Massachusetts, Texas and California.
- Claim Depot: 6,585 Texas residents and 540 Massachusetts residents, which comes to at least 7,125 across those two states. Claim Depot also reports a California filing but gives no California number.
The most likely explanation is that 6,585 is the Texas figure and was repeated as a national total, but the sources do not settle it. Read the affected population as between roughly 6,585 and 7,125 or more, with California's count still unknown.
Data types. DataBreachCaseFile and Data Breach Legal Team both say the Texas filing lists:
- Full name
- Social Security number
- Date of birth
- Home address
- Phone number
- Wage and compensation information
- Tax return information
- Direct deposit account details
Class Action U says the company "has not published a full list of categories" and describes the affected individuals as clients. Data Breach Legal Team lists the same categories but then says in its own text that they "have not been detailed." The wage, tax return and direct deposit fields point strongly to payroll or HR records. That suggests employees or former employees may make up a large share of the victims, which would differ from Class Action U's description of them as clients.
The claimed haul. Claim Depot reports that INC Ransom's post claimed 800 GB of confidential data. According to that report, the post listed client information involving major firms and government entities, contracts, NDAs, closed deals, personal and investment data, project files and drawings, planning documents, accounting data, investment memorandums, audits covering 2021 to 2026, and investor information. None of this is confirmed by the company. If the claim is accurate, the corporate and investor data at risk would go well beyond the personal records covered by the state notifications.
Why It Matters
The six-month notification gap. Detection on March 24 and first notices on October 1 are 191 days apart. Class Action U argues that this delay is common in incidents involving large file volumes, because the company has to work out whose data sits in which files. During that window, though, a leak-site claim was reportedly public, and the affected people had no warning that their SSNs and bank routing details might be circulating.
Commercial real estate data is valuable to extortionists. A firm that manages leasing, development and investment for institutional and high-net-worth clients holds deal documents, investor records and tenant financials alongside its own payroll data. The data categories INC Ransom reportedly listed match what an extortion operator would use for pressure on several fronts: the company, its clients and its investors.
Payroll data enables fraud. An SSN, date of birth, wage history and direct deposit details together are enough for tax refund fraud, payroll diversion and convincing identity theft. That risk lasts well beyond any credit monitoring period.
Unrelated campaigns. The source set includes a ThreatPaper analysis of Cl0p's mid-2026 mass exploitation of PTC Windchill (CVE-2026-12569) and a substitute breach notice from Colonial Presbyterian Church in Kansas City. Neither is linked to Lincoln in any source. They are mentioned here only so readers do not conflate them with this incident.
The Attack Technique
The initial access vector has not been disclosed. None of the sources describes how the intruder got in, how long they were present before detection on March 24, or whether files were encrypted as well as stolen.
If INC Ransom's claim is accurate, the group's publicly documented methods since it appeared in 2023 give defenders useful context. These are general observations about the group and not confirmed for this incident:
- Initial access through exploited internet-facing appliances (VPN and remote-access gateways), spear-phishing, and purchased or stolen valid credentials.
- Living off the land with built-in Windows tools, network scanners and legitimate remote management software for discovery and lateral movement.
- Data staging and exfiltration before encryption, using archiving tools and cloud sync or file transfer utilities, followed by double extortion through its leak site.
An 800 GB claimed theft fits that pattern: a long, quiet collection phase before any disruptive action. Volume on that scale should be visible in egress monitoring.
What Organizations Should Do
- Monitor and limit large outbound transfers. Alert on unusual egress volumes and on cloud sync or file transfer tools (rclone, MEGA clients and similar) running on servers. Hundreds of gigabytes leaving a network should not go unnoticed.
- Separate HR and payroll data. Keep SSNs, tax forms and direct deposit records out of general file shares. Restrict them to dedicated, access-logged systems, and remove records past their retention period.
- Harden edge access. Patch VPN, remote-access and other internet-facing appliances quickly. Enforce phishing-resistant MFA for all remote access, and check for remote management tools nobody approved.
- Prepare for payroll diversion and tax fraud. Require out-of-band verification for any change to direct deposit details. If your workforce data may be exposed, encourage employees to get IRS Identity Protection PINs.
- Plan for faster scoping. Keep an up-to-date map of where personal data lives so that, after an incident, working out who was affected takes weeks rather than six months.
- For affected individuals: freeze credit with all three bureaus, enroll in any monitoring the company offers, request an IRS IP PIN, watch bank accounts linked to direct deposit, and treat unexpected calls or emails that mention the breach as possible phishing.
Sources: Lincoln Property Data Breach Exposes Sensitive Personal Information | Lincoln Property Company Commercial Data Breach Lawsuit - Class Act... | Lincoln Property Company Commercial LLC Data Breach Notification Le... | Lincoln Property Company Commercial LLC Data Breach 2026 | Security Breach Notices Office of the Vermont Attorney General | Lincoln Property Company Advises on Acquisition of Three 1031 Excha... | iPublish MarketPlace - LegalsLegals & Public Notices | Cl0p and PTC Windchill: The Custom Implant That Turned Engineering...