
Castle Group, a property management company based in Plantation, Florida, disclosed a data breach involving unauthorized access to its computer network. The company manages residential communities across the United States.
The breach was reported to state regulators on Aug. 26, 2026. According to those filings, 38 Massachusetts residents and 5 Vermont residents were among those affected.
The breach involved a ransomware attack on Castle Group's network. An unauthorized actor may have gained access to the company's network environment during a period from September 2025 to on or about February 2026.
On Feb. 17, 2026, a ransomware group known as Qilin posted a claim on the dark web, asserting that it had obtained data from the organization.
After learning of the unauthorized access, Castle Group launched an investigation with the help of external cybersecurity professionals. Following an extensive forensic investigation, the company determined that the impacted systems contained personal information belonging to affected individuals.
The types of personal information exposed included names, Social Security numbers, government identification numbers, financial account codes, credit and debit account information and health records.
Castle Group is offering affected individuals a complimentary membership in identity theft protection services through Cyberscout, a TransUnion company. Affected individuals must enroll within a specified time frame from the date of their notification letter.
The company has set up a dedicated toll-free response line to handle questions from affected individuals. The response line is staffed with professionals familiar with the incident and is available Monday through Friday from 8 a.m. to 8 p.m., excluding holidays.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)