JRK Property Holdings, Inc., a large apartment ownership and management company headquartered in Los Angeles, has notified the California Attorney General of a data security incident that may have exposed sensitive personal and financial information belonging to thousands of residents and applicants. Companies that manage this volume of sensitive tenant data have a responsibility to protect it from unauthorized access.
JRK Property Holdings’s Data Breach Investigation
According to a filing submitted to the California Office of the Attorney General and published on July 28, 2026, JRK Property Holdings disclosed a data security incident affecting 11,120 individuals. The categories of information reportedly involved include names, addresses, Social Security numbers, driver’s license numbers, government-issued identification numbers, financial account information, and other personal information. JRK Property Holdings stated in its filing that it notified affected individuals by U.S. Mail.
JRK Property Holdings is one of the larger multifamily apartment owners and operators in the United States, managing tens of thousands of units across numerous states. A company of this scale routinely collects and retains substantial amounts of personal and financial information from current residents, former residents, and rental applicants alike, including the kind of identity and financial documentation typically required during a standard rental application and screening process. This means a single data security incident at a company like JRK Property Holdings has the potential to affect people well beyond its current tenant base, including individuals who applied for housing but never actually moved in.
The California Attorney General’s data breach notification database, where this filing appears, requires companies doing business in California to disclose breaches affecting California residents, but a state filing does not always include a full narrative explaining how an incident occurred, when it was discovered, or how it was contained. As of this notice’s publication, JRK Property Holdings has not released additional public detail about the incident beyond what is reflected in the state filing.
Property management and rental housing companies have increasingly become targets for cybercriminals because of the depth of financial and identity documentation collected during the tenant screening and leasing process. Rental applications commonly require Social Security numbers, government-issued identification, income verification, and sometimes bank account information, all of which is highly valuable to identity thieves if exposed. The combination of Social Security numbers, driver’s license numbers, and financial account information reportedly involved in this incident gives criminals nearly everything needed to open new lines of credit, file fraudulent tax returns, or attempt to take over a victim’s existing financial accounts.
Unlike a compromised payment card, which can typically be canceled and reissued within days, a stolen Social Security number or driver’s license number cannot simply be replaced. This means individuals affected by an incident of this scope may need to remain vigilant for signs of fraud well beyond the initial notification period, potentially for years. Because JRK Property Holdings operates across many states and manages a large number of individual apartment communities, current or former residents of any JRK-managed property, not just those in California, should consider whether they may have been affected, even if this particular filing was made with the California Attorney General.
As with any data breach involving financial and identity information, affected individuals should also remain alert to opportunistic phishing attempts. Scammers frequently exploit news of a real breach by sending fraudulent emails, texts, or letters posing as the affected company, a credit monitoring service, or a law firm, in an effort to trick victims into providing additional personal or financial information.
Notification timelines and requirements vary from state to state, and a company operating in dozens of states, as JRK Property Holdings does through its many managed apartment communities, may end up notifying residents in different jurisdictions at different times depending on each state’s specific legal requirements. California law generally requires notification to affected residents and the Attorney General within a defined window after a breach is discovered, though the exact discovery date and containment timeline for this particular incident were not included in the public filing reviewed for this article.
When Did This Breach Occur?
JRK Property Holdings’s data breach notification was published to the California Attorney General’s data breach notification database on July 28, 2026. The filing does not specify the exact date the underlying incident occurred or when it was first discovered, and JRK Property Holdings has not publicly disclosed this information elsewhere. Individuals who received a direct notice by mail may have been given more specific timing details.
What Information Was Breached?
Per JRK Property Holdings’s filing with the California Attorney General, the categories of information involved in this breach include names, addresses, Social Security numbers, driver’s license numbers, government-issued identification numbers, financial account information, and other personal information. The company reported that 11,120 individuals were affected. Anyone who received a direct notice from JRK Property Holdings should review it carefully, as it may specify exactly which categories of their personal information were involved.
What You Can Do
If you have received notice that your information was involved in the JRK Property Holdings data breach, or believe you may have applied to or resided at a JRK-managed property and may have been affected, consider taking the following steps:
- Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion), given the exposure of Social Security numbers and financial account details.
- Review your bank and credit card statements closely for any unauthorized charges or new accounts you do not recognize.
- Monitor your credit reports regularly for new inquiries or accounts you did not open.
- Be cautious of unsolicited calls, emails, or letters referencing this breach, since scammers often exploit breach news to run phishing scams.
- Keep any notification letter you receive, as it may be needed to support a claim or legal action.
File a Data Breach Lawsuit Against JRK Property Holdings
If your personal or financial information was exposed as a result of this data breach, you may be entitled to compensation. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.