Ransomware victim disclosure
← All victimsBerkadia Commercial Mortgage LLC
Claimed by Hunters International · listed 2 months ago
Status timeline
- Listed
Mar 20, 2026
- Data leaked
At a glance
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Mar 20, 2026
About the victim
AI dossier — public-source company profileBerkadia Commercial Mortgage LLC is a leading commercial real estate finance company and mortgage banker operating across the United States. It is a joint venture between Berkshire Hathaway and Jefferies Financial Group, offering loan origination, servicing, and investment sales services. The firm manages one of the largest commercial mortgage servicing portfolios in the country.
- Industry
- Commercial Real Estate Finance & Mortgage Banking
- Address
- 200 W 57th St, New York, NY 10019, United States
- Employees
- 500-1000
- Founded
- 2009
Attack summary
Severity: critical — Confirmed exfiltration claim of over 5 million Salesforce records containing PII at scale from a major financial services firm, representing a large-volume regulated data exposure with imminent threatened publication.Hunters International claims to have exfiltrated over 5 million Salesforce records containing PII and internal corporate data from Berkadia Commercial Mortgage LLC, with a final deadline of 22 March 2026 before public release and additional unspecified disruptive actions.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce CRM records
- Personally Identifiable Information (PII)
- Internal corporate data
What the group claims
Over 5M Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 22 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 19 Mar 2026 | Warning: FINAL WARNING
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
