Millennium Partners Management LLC, a New York real estate developer, has confirmed a data breach affecting some of its customers and employees. Its notice dated September 16, 2026 says an unauthorized party accessed its network between April 24 and April 26, 2026. The notice says data was "accessed and acquired" and that it may have included Social Security numbers. The company has not said how many people were affected, and none of the sources give a victim count. The breach-tracking site ClaimDepot reports that the ransomware group The Gentlemen claimed the attack in early May. The company has not confirmed that claim.
What Happened
The timeline comes from the company's notice on its own website (S2). Legal-claims and news sites repeat it (S1, S3, S4):
- April 24 to 26, 2026: An unauthorized party accessed the network "during times" in this window.
- April 27, 2026: Millennium found what it called a "network disruption." It secured the network and brought in outside cybersecurity specialists.
- May 5, 2026: ClaimDepot (S1) reports that The Gentlemen posted on a Tor leak site. The post said the group had the company's data and would publish it within eight to nine days. No other source repeats this, and it has not been independently verified.
- July 9, 2026: The investigation confirmed that data had been accessed and acquired, and that it contained personal information.
- September 16, 2026: The company posted its public notice. That was about five months after discovery and more than two months after the data exfiltration was confirmed.
The company calls the event a "network disruption." That wording, together with the leak-site claim reported by S1, fits a ransomware attack where data was stolen and systems were encrypted. Millennium has not used the word ransomware, has not named an attacker, and has not said whether it paid a ransom.
What Was Taken
The company's notice lists only one data type: Social Security numbers, which it says "may have" been involved. ClaimDepot (S1) also lists names, dates of birth, addresses, government IDs, medical information and financial information. It does not say where those additional categories come from, and the company's notice does not confirm them. They should be treated as unverified.
The affected groups are customers and employees. For a real estate developer, "customers" could include residential buyers, tenants and condominium owners. Those relationships usually generate identity and financial records. This is an inference, and the company has not said which customer records were exposed.
No record count or victim count has been disclosed in any of the sources reviewed. We also found no state attorney general filing with a figure among these sources.
Why It Matters
Real estate developers hold records that are useful for identity fraud, including Social Security numbers, financial documents and ID copies from purchase and leasing files. Their security programs are often less mature than those at banks. When stolen data is posted on a leak site, as S1 reports The Gentlemen threatened, it can be copied and resold indefinitely. That makes the long gap before public notice more serious.
Don't mix this up with other companies. Several of the sources are about different firms, and the similar names make confusion likely:
- S6 (CoinShares) and S7 (CPA Practice Advisor) cover AI voice-cloning phishing ("vishing") attacks in August 2026. Those attacks reportedly targeted hedge funds including Point72, Citadel, Two Sigma and Millennium Management. Millennium Management is a separate investment firm and has no link to Millennium Partners Management, the real estate company.
- S8 is a LinkedIn profile for an IT employee who lists "Millennium Partners." The attached company description is for Millennium Management, the hedge fund. This looks like an automated mismatch and tells us nothing about this breach.
- S5 describes a separate social engineering breach at Apollo Global Management between July 6 and 10, 2026.
None of these sources connects the Millennium Partners intrusion to the hedge-fund vishing campaign. The timing also rules out a direct link: Millennium Partners was breached in April, and the hedge-fund attacks were in August.
The Attack Technique
The company has not said how the attacker got in. Its notice covers only when the access happened and when it was found. If The Gentlemen claim is accurate, the pattern would be typical double extortion: get into the network, steal data over several days, cause disruption, then threaten to publish the data. The three days between first access and detection is a short dwell time. It was still long enough to take data out.
The sources don't tell us the initial access vector (phishing, stolen credentials, an exploited edge device, or remote access abuse), any indicators of compromise, or whether encryption was used. The vishing techniques described in S7 are a relevant general threat to New York financial and property firms. Nothing in the sources ties them to this incident.
What Organizations Should Do
- Monitor outbound data flows. Here data was stolen within about 72 hours. Alert on large or unusual outbound transfers, especially to cloud storage and file-transfer services, and don't rely only on detecting encryption.
- Minimize and segment SSN stores. Real estate firms should audit where Social Security numbers from buyers, tenants and employees are stored. Remove records you no longer need, and keep the rest in segmented, access-controlled systems.
- Harden remote access and help-desk processes. Require phishing-resistant MFA on VPN, RDP and admin accounts. Require call-back verification for any password reset or access request made by phone, since voice-cloning attacks (S7) target exactly those workflows.
- Watch leak sites for your own name. A threat-intelligence feed that tracks ransomware leak sites can tell you your data is being advertised before your forensic investigation is finished.
- Shorten the path to notification. Pre-arrange incident response, data review and notification vendors so the gap between confirming theft and notifying people is weeks, not months.
- Advise affected individuals. People who get a notice should place credit freezes with TransUnion, Experian and Equifax, and check their free reports at annualcreditreport.com. They can call Millennium's TransUnion call center at 1-800-405-6108, 8 a.m. to 8 p.m. ET, Monday to Friday.
Sources: Millennium Partners Data Breach Exposes Social Security Numbers | Notice of Data Security Incident - Millennium Partners | Millennium Partners Data Breach Exposes SSNs; Lawsuit Possible | Millennium Partners Management Reports Data Security Breach Affecti... | Apollo Global Management Data Breach Lawsuit - Class Action U | Beyond the Coldcard exploit: AI and financial security | How Accounting Firms Can Protect Against the Rising Threat of ... | kevin ryan