The Rhysida ransomware-as-a-service group has listed RealManage, a homeowners association (HOA) management company based in Plano, Texas, on its dark web leak site. The group says it has published 1.84 TB of stolen data. Three trackers recorded the listing on 9 October 2026: QPulse, HackerFeeds and Cyber Threat Intelligence. According to the group's own description, the dump holds Social Security numbers, bank routing and account numbers, signed tax forms and personal debt records for "hundreds of American HOAs and thousands of homeowners." No source available for this brief carries a statement from RealManage, a regulator filing or a breach notification. Everything below about the contents of the dataset comes from the attacker's claim as relayed by the trackers. HackerFeeds says outright that the details "have not been independently verified."
What Happened
RealManage is a privately held community association management company. It was founded in 2002, is backed by private equity firm American Securities, and describes itself as one of the largest and fastest-growing firms in its sector in the US (HackerFeeds, quoting the leak-site entry). Rhysida posted the company on its leak site on 9 October 2026 and says the 1.84 TB dataset is already public, not held back for ransom.
Some details are uncertain or differ between sources:
- Breach date unknown. HackerFeeds gives both "Date of Breach" and "Discovery Date" as 2026-10-09, but that is the day of the listing, not the intrusion. Ransomware.live says Rhysida posts victims an average of 37.6 days after the estimated attack date. The leaked records reportedly include assessments through September 2026 (QPulse, HackerFeeds), so the data was taken in or after September.
- Sector classification differs. QPulse files the incident under Real Estate, Property Management and Financial Services. HackerFeeds and Cyber Threat Intelligence use Professional Services.
- Severity ratings differ. QPulse rates it Critical (90/100). HackerFeeds rates it High.
- No victim confirmation. None of the eight sources includes a RealManage statement. Whether systems were encrypted, whether a ransom was demanded, and how many people are affected are all unknown.
What Was Taken
According to Rhysida's claim, as reported by QPulse and HackerFeeds, the 1.84 TB dataset includes:
- Tax and identity records: W-9 forms with SSNs, addresses and signatures. IRS 1099-MISC/NEC e-file transmissions covering 2014 to 2025, with thousands of vendor TINs and SSNs.
- Banking data: ACH debit files with routing and account numbers, USAA brokerage statements and signed bank signature cards.
- Debt and hardship records: HOA assessments through September 2026, bankruptcy filings, late-fee waivers and hardship letters from homeowners asking for payment plans.
- Personal documents: HUD-1 settlement statements showing buyer names, purchase prices and mortgage details. Signed waivers with addresses. HOA election ballots with voter names.
- Internal databases: SQL Server databases named RM_Warehouse, RM_Sales, RM_Portals, CiraNetIdentity (portal accounts) and CiraBooks_GL (general ledger).
- File and mail shares: CiraMail$, CiraDocs$ and SalesDocs$.
No source gives a count of affected people. "Hundreds of HOAs and thousands of homeowners" is the attacker's wording. Treat it as unverified until RealManage or a state attorney general filing gives a figure.
Why It Matters
A single HOA management firm holds sensitive records for many separate communities. One breach therefore exposes residents who never dealt with RealManage directly and may not know it holds their data. The combination of SSNs, bank account numbers, signatures and debt history is well suited to identity theft, ACH fraud and targeted scams. Debt and hardship records are especially useful for social engineering: a fake "payment plan" message aimed at a homeowner who is known to be behind on assessments is highly believable. The CiraNetIdentity portal account database also creates a risk of credential stuffing against resident portals and other services.
This listing fits Rhysida's recent pattern of targeting firms that handle large amounts of client financial records:
- In September, QPulse reported a 253 GB leak from the Italian accounting and law firms NEAD SRL and NEAD PRO. It included tax signing keys and SEPA mandates.
- DeXpose reported a September listing of US-based Professional Retail Services that included signed checks and credit reports.
- CybelAngel reports that the group claimed 5.79 TB from Berlin's state network on 28 August and demanded 30 BTC.
Reported victim counts for the group vary:
- Ransomware.live and Cyber Threat Intelligence: 295 victims since June 2023, though Cyber Threat Intelligence's own header shows 223.
- CybelAngel: "close to 300" victims across 39 countries.
- Ransomware.live: 42 countries.
The Attack Technique
None of the sources says how RealManage was breached. Rhysida's general methods are documented: phishing for initial access (MITRE T1566), Cobalt Strike for post-exploitation, and double extortion that combines data theft with encryption (Cyber Threat Intelligence, Ransomware.live). CybelAngel cites CISA-documented TTPs and notes technical overlaps with the defunct Vice Society. Ransomware.live reports that 49.4% of Rhysida victims with a known domain had infostealer exposure beforehand, so stolen credentials are a likely way in. Sources disagree on the encrypted file extension: one copy of the shared profile says ".ryshida", while Ransomware.live's metadata lists ".rhysida". Defenders should hunt for both.
For background only: Sophos has documented "TerminalFix," a ClickFix variant that tricks users into running PowerShell in Windows Terminal. In the STAC4924 campaign it delivered Lorem Ipsum Loader and a Python tunneling implant, using DLL sideloading through LockScreenContentServer.exe. Sophos does not link this activity to Rhysida or RealManage. It is included here as a current example of the user-executed initial access that commonly comes before ransomware.
What Organizations Should Do
- Notify and protect affected residents. HOA boards that use RealManage should ask the company directly whether their community's data is in the leak. They should advise residents to freeze their credit, watch bank accounts for unauthorized ACH debits, and treat unexpected payment or "hardship plan" messages as likely fraud.
- Rotate portal credentials and change banking details. Force password resets on resident and vendor portals. Work with banks to monitor or replace the accounts that appear in leaked ACH files and signature cards.
- Monitor for infostealer exposure. With nearly half of Rhysida's victims showing prior infostealer exposure, check for leaked employee and contractor credentials and revoke active sessions, not just passwords.
- Block user-executed script lures. Restrict PowerShell and Windows Terminal for standard users where possible. Alert on browser-spawned shells and on DLL sideloading from user-writable paths, and train staff to recognize ClickFix and TerminalFix prompts.
- Watch for Cobalt Strike and large outbound transfers. Alert on beaconing and on bulk exfiltration from SQL Server hosts and file shares such as CiraDocs$-style repositories.
- Reduce stored PII. Tax transmissions going back to 2014 were reportedly still on disk. Enforce retention limits and encrypt or tokenize SSNs and bank details at rest.
Sources: Rhysida Ransomware Group Leaks 1.84 TB of Data from RealManage QPulse | TerminalFix and Lorem Ipsum Loader enable covert tunneling | Ransomware group rhysida hits RealManage HackerFeeds | RealManage Ransomware Attack by Rhysida (2026) Cyber Threat Intell... | Rhysida - Ransomware.live | Rhysida Ransomware: Attack Methods, IOCs and Defence 2026 | Rhysida Ransomware Group Leaks 253GB of Data from Italian Professio... | Rhysida Ransomware Strikes Professional Retail Services - DeXpose