On May 27, 2025, real estate giant RE/MAX appeared on the leak site of the Medusa ransomware group, with 151.80 GB of internal files posted after a ransomware attack. The breach affects anyone whose personal or financial records passed through RE/MAX corporate systems or its vast network of franchise offices, potentially exposing employees, agents, home buyers, sellers, and their families.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Re/Max
Get alerted the next time Re/Max files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Re/Max’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that RE/MAX, founded in 1973 and headquartered in Denver, Colorado, had 151.80 GB of internal files exfiltrated. The data was published on the Medusa leak site on May 27, 2025. Available reporting describes the exposed material as internal files; the precise mix of documents has not been independently verified by third parties. The total number of individuals whose records appear in the leak remains unknown. RE/MAX operates as a global franchisor with approximately 140,000 employees and agents worldwide.
Why This Matters for You and Your Family
When a company that handles home purchases, mortgage applications, and identity verification is breached, the ripple effects reach ordinary families. Real estate records often contain Social Security numbers, bank details, tax returns, driver’s license scans, and contact information for every party involved in a transaction. If your family bought or sold a home through a RE/MAX agent in recent years, portions of that paperwork may now sit in an attacker’s archive. Once stolen, this data fuels identity theft, fraudulent loan applications, and targeted scams that feel personal because they reference your actual address or pending home sale.
Children’s information can also surface when family relocations involve school records or dependent details. The breach therefore concerns not just the person who signed the listing agreement but everyone whose name appears in the supporting files.