On November 10, 2025, the ransomware group known as CoinbaseCartel listed real estate platform Propertyfinder and its PropSpace CRM on its leak site, claiming to have exfiltrated more than 2 TB of internal files. The data includes the full Propertyfinder leads database containing 10 million-plus records, the complete property listings database, and all client information held in the PropSpace CRM system. Anyone who has used Propertyfinder to search for property, submit inquiries, or engage with real estate agents may have personal details now in the hands of criminals.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Propertyfinder
Get alerted the next time Propertyfinder files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Propertyfinder’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the incident stems from a ransomware attack in which attackers gained access to Propertyfinder’s internal systems and exfiltrated large volumes of data before encryption or public disclosure. The leak site lists the compromised databases explicitly: the leads database with over 10 million records, full property listings, and every client record stored in PropSpace CRM. No exact number of affected individuals has been confirmed by the company, but the scale of the leads database alone suggests millions of prospective buyers, sellers, and agents are potentially exposed. Available reporting describes the exposed material as including names, contact details, property preferences, and communications that typically accompany real estate inquiries.
Why This Matters for You and Your Family
When your home search or rental inquiry ends up in a ransomware leak, the consequences reach far beyond spam. The information can be combined with other breached records to build a detailed profile of where you live, how much you can afford, and who else is in your household. For families, this often means children’s names and school-related details surface if they were listed on tenancy applications or family accounts. Once criminals hold this data, it can be sold on underground forums or used directly to impersonate you with banks, utilities, or government agencies. The breach therefore affects not just the person who created the Propertyfinder account but everyone whose information was entered alongside it.
The Doxxing and Identity-Chain Implications
Real estate records are especially dangerous in doxxing chains because they link email addresses, phone numbers, and physical addresses with financial intent. Attackers can cross-reference the leaked leads against credential dumps from other services. A password reused from an old gaming account, for example, can let them seize that account, then use chat logs or linked phone numbers to map the full household. Public reporting indicates these chains frequently escalate from simple data sales to targeted extortion, swatting, or identity theft. Credential leaks like this one cascade into account takeovers and doxxing chains, which is why protecting gaming accounts belonging to you or your children is now directly relevant.