---
title: "Marcus & Millichap phishing data incident"
description: "Evidence-backed account of Marcus & Millichap phishing data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/marcus-millichap-phishing-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/marcus-millichap-phishing-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/marcus-millichap-phishing-data-incident-2026/stix.json"
---

# Marcus & Millichap phishing data incident

An unauthorized third party used social engineering to obtain one employee's credentials and access certain Marcus & Millichap systems. The incident exposed contact, employment, property-transaction, date-of-birth, and internal company information.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Organization-reported operational and network impact.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

An unauthorized third party used social engineering to obtain one employee's credentials and access certain [Marcus & Milli](https://www.marcusmillichap.com/)chap systems. [3](#source-3)

## Impact

The incident exposed contact, employment, property-transaction, date-of-birth, and internal company information. [2](#source-2) [3](#source-3)

Documented data types include:

- Names — Names of employees, independent contractor agents, and clients in the company disclosure; names are also listed in the HIBP corpus. [2](#source-2) [3](#source-3)
- Employment information — Employer names and job titles listed for records in the HIBP incident corpus. [2](#source-2) [3](#source-3)
- Property transaction information — Certain property transaction information identified in the company disclosure. [2](#source-2) [3](#source-3)
- Dates of birth — Dates of birth for employees and independent contractor agents. [2](#source-2) [3](#source-3)
- Contact information — Email addresses and phone numbers in the company disclosure; HIBP additionally lists physical addresses in its corpus. [2](#source-2) [3](#source-3)

A cited record reports 1,837,078 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a company-confirmed affected-person count; as of 2026-05-03). [2](#source-2) [3](#source-3)

Marcus & Millichap said it did not believe the incident had materially affected its business, financial condition, or results of operations. [1](#source-1)

The company advised people to remain alert to unsolicited emails or calls, avoid sharing personal information in response to unexpected outreach, and report suspicious activity. [3](#source-3)

The accessed data included non-sensitive company materials such as SharePoint templates, forms, and reports. [3](#source-3)

The company found no indication that financial account numbers, Social Security numbers, driver's license numbers, passport information, or similar government-issued identification data were accessed. [3](#source-3)

## Timeline

### April 12, 2026 — Public disclosure

Publication date of the initial company cybersecurity-incident statement. [3](#source-3)

### April 12, 2026 — Documented event

Day-level incident date in HIBP; the first company statement was also published that day but describes the identification as recent rather than giving a precise intrusion timestamp. [2](#source-2) [3](#source-3)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

An unauthorized third party used social engineering techniques to obtain a single employee's login credentials and access certain company systems. [1](#source-1) [3](#source-3)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

The threat actor exfiltrated certain customer, employee, and internal business data. Marcus & Millichap said it identified and contained the incident within one hour, secured all affected systems, and added security measures. Marcus & Millichap activated its incident-response protocols, engaged outside cybersecurity experts, and notified law enforcement. The threat actor released the accessed data, and the company said the released data was consistent with the data categories in its FAQ. The company reported no disruption to operations or business continuity and said no other portions of its network environment were impacted. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [3](#source-3)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/marcus-millichap-phishing-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Quarterly Report on Form 10-Q for the quarter ended March 31, 2026

regulatory · Marcus & Millichap, Inc. · May 7, 2026

<https://ir.marcusmillichap.com/sec-filings/all-sec-filings/content/0001628280-26-032300/mmi-20260331.htm>

<a id="source-2"></a>

### Marcus & Millichap breach record

advisory · Have I Been Pwned · May 3, 2026

<https://haveibeenpwned.com/api/v3/breach/MarcusMillichap>

<a id="source-3"></a>

### Marcus & Millichap Releases Information Regarding Cybersecurity Incident

official · Marcus & Millichap, Inc. · Apr 12, 2026

<https://www.marcusmillichap.com/news-events/press/2026/04/marcus-millichap-releases-information-regarding-cybersecurity-incident>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   April 2026 Marcus & Millichap phishing incident: Marcus & Millichap April and May 2026 incident disclosures
2. **Exposed Record Count · 100% confidence · current**  
   Marcus & Millichap customer, workforce, transaction, and company-data exposure: 1,837,078 record
3. **Affected Organization · 100% confidence · current**  
   April 2026 Marcus & Millichap phishing incident: Marcus & Millichap, Inc.
4. **Disclosed At · 100% confidence · current**  
   Marcus & Millichap April and May 2026 incident disclosures: 2026-04-12
5. **Resulted In · 100% confidence · current**  
   April 2026 Marcus & Millichap phishing incident: An unauthorized third party used social engineering techniques to obtain a single employee's login credentials and access certain company systems.
6. **Resulted In · 100% confidence · current**  
   April 2026 Marcus & Millichap phishing incident: Marcus & Millichap said it did not believe the incident had materially affected its business, financial condition, or results of operations.
7. **Resulted In · 100% confidence · current**  
   Marcus & Millichap April and May 2026 incident disclosures: The company advised people to remain alert to unsolicited emails or calls, avoid sharing personal information in response to unexpected outreach, and report suspicious activity.
8. **Exposed Data Category · 100% confidence · current**  
   Marcus & Millichap customer, workforce, transaction, and company-data exposure: Names
9. **Resulted In · 100% confidence · current**  
   Marcus & Millichap customer, workforce, transaction, and company-data exposure: The accessed data included non-sensitive company materials such as SharePoint templates, forms, and reports.
10. **Occurred At · 90% confidence · current**  
   April 2026 Marcus & Millichap phishing incident: 2026-04-12
11. **Resulted In · 100% confidence · current**  
   Marcus & Millichap customer, workforce, transaction, and company-data exposure: The company found no indication that financial account numbers, Social Security numbers, driver's license numbers, passport information, or similar government-issued identification data were accessed.
12. **Exposed Data Category · 100% confidence · current**  
   Marcus & Millichap customer, workforce, transaction, and company-data exposure: Employment information
13. **Affected Organization · 100% confidence · current**  
   Marcus & Millichap customer, workforce, transaction, and company-data exposure: Marcus & Millichap, Inc.
14. **Resulted In · 100% confidence · current**  
   April 2026 Marcus & Millichap phishing incident: Marcus & Millichap customer, workforce, transaction, and company-data exposure
15. **Resulted In · 100% confidence · current**  
   April 2026 Marcus & Millichap phishing incident: The threat actor exfiltrated certain customer, employee, and internal business data.
16. **Exposed Data Category · 100% confidence · current**  
   Marcus & Millichap customer, workforce, transaction, and company-data exposure: Property transaction information
17. **Resulted In · 100% confidence · current**  
   April 2026 Marcus & Millichap phishing incident: Marcus & Millichap said it identified and contained the incident within one hour, secured all affected systems, and added security measures.
18. **Exposed Data Category · 100% confidence · current**  
   Marcus & Millichap customer, workforce, transaction, and company-data exposure: Dates of birth
19. **Resulted In · 100% confidence · current**  
   April 2026 Marcus & Millichap phishing incident: Marcus & Millichap activated its incident-response protocols, engaged outside cybersecurity experts, and notified law enforcement.
20. **Resulted In · 100% confidence · current**  
   Marcus & Millichap customer, workforce, transaction, and company-data exposure: The threat actor released the accessed data, and the company said the released data was consistent with the data categories in its FAQ.
21. **Exposed Data Category · 100% confidence · current**  
   Marcus & Millichap customer, workforce, transaction, and company-data exposure: Contact information
22. **Resulted In · 100% confidence · current**  
   April 2026 Marcus & Millichap phishing incident: The company reported no disruption to operations or business continuity and said no other portions of its network environment were impacted.

</details>
