Cornerstone Residential SQL Dump Allegedly Leaked on Cybercrime Forum

A threat actor claims to have leaked a Cornerstone Residential SQL database containing internal website data, roles and API-related credentials.
Screenshot of a cybercrime forum post claiming a full SQL database dump from Texas property management company Cornerstone Residential, with sensitive details redacted.
A forum post claims a full SQL database dump from Cornerstone Residential containing user roles, preferences and API-related credentials.

A threat actor claims to have breached Cornerstone Residential, a Texas property management company, and published what is described as a full SQL database dump containing internal website and administrative data.

The claim was posted on Aug. 24 and identifies mycornerstonetx.com as the affected site. The threat actor says the database includes user preferences, role information, Elementor API access credentials and administrator IP-related location data.

Cornerstone Residential provides property and asset management services in Corpus Christi, Dallas and San Antonio, according to the company’s website. Its services include residential and commercial property management, property marketing and asset oversight.

Claim centers on website administration data

The alleged leak appears more focused on the company’s website infrastructure and administrative environment than on a large customer dataset.

The threat actor claims the SQL dump contains user preference information, account roles and credentials or secrets associated with Elementor integrations. If authentic, exposed API credentials could create additional risk depending on the privileges attached to them and whether they remain active.

The post also claims administrator IP location data is present in the database. BreachNews is not reproducing any credentials, IP addresses, access tokens, secrets or other sensitive technical details from the alleged dump.

Scope of customer exposure remains unclear

The forum post does not provide enough information to establish whether tenant, property owner or applicant data is included in the database.

Cornerstone Residential’s public website includes contact forms and information related to property management services, but the threat actor did not specifically claim that tenant records, lease documents, payment information or other customer data was exposed.

BreachNews has not independently verified the full SQL dump or confirmed that the database originated from Cornerstone Residential systems.

No public statement from Cornerstone Residential

Cornerstone Residential had not issued any public statement addressing the alleged breach at time of publication.

The company’s website remained accessible when checked by BreachNews. Cornerstone Residential describes itself as a property management company founded by experienced industry professionals and says it operates across multiple Texas markets.

Until the company confirms the incident or additional evidence emerges, the claim should be treated as unverified.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site