TruAmerica Multifamily, a Los Angeles-based real estate investment and asset management firm that owns and operates multifamily apartment communities across the United States, may have experienced a data breach after a ransomware group claimed to have compromised its systems in September 2026.
Companies that manage large volumes of resident, investor, and employee data have a responsibility to protect that information from unauthorized access, and a breach at a firm of TruAmerica’s size and scope could put a significant number of people at risk.
TruAmerica Multifamily’s Data Breach Investigation
Attorneys working with Class Action U are looking into whether a class action lawsuit can be filed on behalf of individuals whose personal information may have been exposed in a possible TruAmerica Multifamily data breach. According to reports, a ransomware group calling itself Termite posted about an attack on TruAmerica Multifamily to a dark web leak site on September 22, 2026, claiming to have exfiltrated data from the company’s systems. As of this writing, TruAmerica Multifamily has not publicly confirmed the incident, and no official notification letters describing the scope of the breach have surfaced.
Ransomware groups like Termite typically operate using a double-extortion model: they first infiltrate a victim’s network and quietly copy sensitive files, then deploy encryption malware that locks the victim out of its own systems. The group then demands payment twice over, once to restore access to encrypted data and again to prevent the stolen files from being published or sold. This approach has become increasingly common across nearly every industry, and real estate and property management firms are no exception. These companies routinely collect and store large volumes of highly sensitive information, including Social Security numbers, financial account details, lease and payment histories, and government-issued identification, making them attractive targets for cybercriminals looking to monetize stolen data quickly.
When a company’s investigation into a reported cyberattack is still ongoing, it is common for a firm to take weeks or even months before issuing formal notification letters to affected individuals, as required under most state data breach notification laws. That process typically involves determining what information was accessed, identifying who was affected, and coordinating with regulators and forensic investigators before a public statement is made. Until that process concludes, the exact nature and scope of the TruAmerica Multifamily incident remains unclear.
Property management and real estate investment firms are an especially attractive target for this kind of attack because of the sheer breadth of personal information that flows through their systems over the life of a single tenancy or investment relationship. A resident applying for an apartment may hand over a Social Security number, bank account and routing numbers, pay stubs, prior addresses, and a full credit history, while an investor in one of the firm’s funds may share tax identification numbers, wire transfer instructions, and detailed financial statements. Employees add another layer of exposure, since payroll systems typically store direct deposit information alongside Social Security numbers and benefits enrollment records. When any of these systems is compromised, the resulting exposure can touch multiple categories of people at once, not just customers in the traditional sense.
Even without a formal company statement, the mere possibility that Social Security numbers, financial information, or other personal identifiers were exposed can create real risk for the people affected. Stolen personal data is often bundled together and sold on dark web marketplaces, where it can be used to open fraudulent credit accounts, file false tax returns, or craft convincing phishing schemes that target victims using their own real information. The longer it takes for a company to notify the people impacted by a breach, the more time criminals may have to exploit that information before anyone knows to watch for warning signs.
Class Action U is committed to helping people understand their rights when a company entrusted with their personal information experiences a security incident like this one. If you are a current or former employee, investor, or resident connected to TruAmerica Multifamily, it is worth staying alert for any official communication from the company and taking the precautionary steps outlined below.
When Did This Breach Occur?
The exact timeline of the alleged TruAmerica Multifamily breach has not been confirmed by the company. Reports first surfaced on September 22, 2026, when the ransomware group Termite posted about an attack on its dark web leak site, with the estimated date of the attack itself listed as that same day. A separate dark web monitoring service similarly reported Termite’s claim. TruAmerica Multifamily had not issued a public statement confirming or denying the incident at the time this page was published, so a confirmed breach detection date, notification date, and full scope of the incident are not yet available.
What Information Was Breached?
TruAmerica Multifamily has not publicly disclosed what, if any, specific categories of personal information may have been affected. Ransomware groups that use a double-extortion model frequently target the kinds of records commonly held by real estate investment and property management firms, including names, Social Security numbers, financial account information, and lease or payment records, but no such list has been confirmed for this incident. This page will be updated if additional details become available.
What You Can Do
If you believe you may have been affected by the TruAmerica Multifamily incident, consider taking the following precautionary steps:
- Monitor your bank and credit card statements closely for any unauthorized charges.
- Request a free copy of your credit report and review it for accounts you don’t recognize.
- Consider placing a fraud alert or credit freeze with the major credit bureaus.
- Be cautious of unexpected emails, calls, or texts asking you to verify personal information.
- Keep any notification letter you may receive from TruAmerica Multifamily, as it can serve as evidence that you were affected.
File a Data Breach Lawsuit Against TruAmerica Multifamily
If you were affected by the TruAmerica Multifamily data breach, you may be entitled to compensation for the time, expense, and risk that comes with having your personal information exposed. A class action lawsuit could also push the company to strengthen the safeguards it uses to protect the data it collects.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.