Ransomware victim disclosure
← All victimsBerkadia Commercial Mortgage LLC
Claimed by Shinyhunters · listed 3 months ago
Status timeline
- ListedMar 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Mar 20, 2026
About the victim
AI dossier — public-source company profileBerkadia Commercial Mortgage LLC is a large-scale commercial real estate finance company headquartered in the United States, operating as a joint venture between Berkshire Hathaway and Jefferies Financial Group. The firm provides mortgage banking, investment sales, and loan servicing across the commercial real estate sector. It is one of the largest commercial mortgage banking and loan servicers in the country.
- Industry
- Commercial Real Estate Finance & Mortgage
- Employees
- 1001-5000
- Founded
- 2009
Attack summary
Severity: critical — Over 5 million records containing PII have been exfiltrated from a major financial services firm; the scale and sensitivity of the data (PII at scale from a regulated financial institution) meets the critical threshold.ShinyHunters claims to have exfiltrated over 5 million Salesforce records containing PII and internal corporate data from Berkadia, issuing a final deadline of 22 March 2026 to negotiate before public release and threatened additional 'digital problems.'
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce CRM records
- Personally Identifiable Information (PII)
- Internal corporate data
What the group claims
Over 5M Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 22 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 19 Mar 2026 | Warning: FINAL WARNING
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

