Summary
- Environment: Organization-reported operational and network impact.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
An unauthorized third party used social engineering to obtain one employee’s credentials and access certain Marcus & Millichap systems. [3]
Impact
The incident exposed contact, employment, property-transaction, date-of-birth, and internal company information. [2][3]
Documented data types include:
- Names — Names of employees, independent contractor agents, and clients in the company disclosure; names are also listed in the HIBP corpus. [2][3]
- Employment information — Employer names and job titles listed for records in the HIBP incident corpus. [2][3]
- Property transaction information — Certain property transaction information identified in the company disclosure. [2][3]
- Dates of birth — Dates of birth for employees and independent contractor agents. [2][3]
- Contact information — Email addresses and phone numbers in the company disclosure; HIBP additionally lists physical addresses in its corpus. [2][3]
A cited record reports 1,837,078 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a company-confirmed affected-person count; as of 2026-05-03). [2][3]
Marcus & Millichap said it did not believe the incident had materially affected its business, financial condition, or results of operations. [1]
The company advised people to remain alert to unsolicited emails or calls, avoid sharing personal information in response to unexpected outreach, and report suspicious activity. [3]
The accessed data included non-sensitive company materials such as SharePoint templates, forms, and reports. [3]
The company found no indication that financial account numbers, Social Security numbers, driver’s license numbers, passport information, or similar government-issued identification data were accessed. [3]
Timeline
Public disclosure
Publication date of the initial company cybersecurity-incident statement.
[3]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
An unauthorized third party used social engineering techniques to obtain a single employee’s login credentials and access certain company systems. [1][3]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
The threat actor exfiltrated certain customer, employee, and internal business data. Marcus & Millichap said it identified and contained the incident within one hour, secured all affected systems, and added security measures. Marcus & Millichap activated its incident-response protocols, engaged outside cybersecurity experts, and notified law enforcement. The threat actor released the accessed data, and the company said the released data was consistent with the data categories in its FAQ. The company reported no disruption to operations or business continuity and said no other portions of its network environment were impacted. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][3]
