ShadowByt3$ Claims Ben Leeds Properties Breach Through AppFolio

ShadowByt3$ claims it compromised Ben Leeds Properties through AppFolio and extracted tenant, lease, vehicle and work order records using Realm-X.
Cropped screenshot of a forum post in which ShadowByt3$ claims to have breached Ben Leeds Properties through its AppFolio environment and used Realm-X to extract data.
ShadowByt3$ claims it gained access to Ben Leeds Properties through AppFolio and used Realm-X to extract work order and other property management data. The screenshot has been heavily cropped because the original forum post was unusually long and contained additional sensitive details, including alleged credentials and resident information.

ShadowByt3$ claims it breached Los Angeles property management company Ben Leeds Properties through its AppFolio environment and used the platform’s Realm-X AI capabilities to extract tenant, work order, lease and operational data.

The threat actor says it maintained access long enough to pull records over several days and claims the exposed material includes rent rolls, signed lease documents, vehicle information, work orders, maintenance notes and other resident data.

ShadowByt3$ also published what it described as active account credentials and claimed Ben Leeds Properties had not changed the password despite repeated warnings. BreachNews is not reproducing or testing those credentials.

Ben Leeds Properties had not issued any public statement confirming the breach at time of publication.

AppFolio access allegedly used to pull resident data

ShadowByt3$ claims the intrusion occurred through Ben Leeds Properties’ AppFolio property management environment.

The group alleges that after gaining initial access, it used Realm-X, AppFolio’s AI suite, to query and export information from work order and property management modules.

AppFolio describes Realm-X as an AI system capable of retrieving operational insights, executing bulk actions and working across property management workflows. The platform also supports maintenance functions involving work orders and resident operations. AppFolio’s Realm-X product page describes those capabilities.

The threat actor’s claim is significant because the alleged abuse does not involve compromising Realm-X itself. Instead, the group says it used legitimate functionality available through a compromised Ben Leeds Properties account to extract data already accessible within the property management environment.

There is currently no evidence that AppFolio’s own infrastructure was breached or that other AppFolio customers were affected.

Work orders allegedly exposed access notes and property details

ShadowByt3$ claims it extracted more than 140,000 historical work order records spanning approximately 15 years.

According to the actor, the records include work order identifiers, timestamps, maintenance categories, property addresses, apartment unit numbers, assigned staff and vendor information.

More concerningly, the group claims free-text maintenance records contain apartment entry instructions, gate codes, lockbox combinations and notes about whether residents had authorized entry while they were away.

If authentic, that information could create physical security risks beyond conventional identity theft because work order records may expose property access instructions and details about apartment vulnerabilities.

BreachNews has not independently verified the claimed 140,000-record count or the presence of access codes throughout the dataset.

Leases, rent rolls and vehicle data also claimed stolen

The actor describes the alleged collection as extending well beyond maintenance records.

Purportedly stolen information includes:

  • Resident names and apartment numbers
  • Monthly rent amounts and outstanding balances
  • Lease start and expiration dates
  • Signed lease agreements and related addendums
  • Parking agreements and vehicle information
  • License plate information and assigned parking spaces
  • Move-out records
  • Property inspection information
  • Service animal accommodation records
  • Resident contact information

The group also claims the archive contains regulatory and credit-reporting forms tied to individual residents.

BreachNews is not reproducing leaked resident information, property access details, signatures or other sensitive material included in the actor’s post.

Credential exposure may explain initial access

Independent threat intelligence provides one possible explanation for the claimed AppFolio compromise.

Security researchers identified infostealer telemetry associated with Ben Leeds Properties that included credentials for the company’s AppFolio tenant. The same corporate account reportedly appeared in several credential records dating from late 2025 through early September 2026.

That does not prove those credentials were used by ShadowByt3$, but it presents a plausible path into the environment that does not require exploitation of an AppFolio vulnerability.

The threat actor has not publicly identified its initial access method beyond claiming it gained access to the company’s AppFolio environment.

Ben Leeds manages thousands of residential units

Ben Leeds Properties says it manages more than 4,000 units across Southern California and Nevada, including apartments, single-family homes, mobile home communities and commercial properties.

The company also says it owns approximately 160 properties in the Greater Los Angeles area.

That scale potentially increases the sensitivity of the alleged breach because a compromised property management platform can contain information linking residents directly to addresses, units, leases, vehicles and maintenance histories.

ShadowByt3$ resumes extortion activity after claimed retirement

The Ben Leeds Properties claim continues ShadowByt3$’s return to public extortion activity after the group previously announced that it was retiring.

BreachNews reported in June that ShadowByt3$ claimed it was shutting down after months of extortion activity.

That retirement proved short-lived. The group later resurfaced with an alleged breach involving Abbott’s LabCentral portal, marking its return to active victim claims.

The latest Ben Leeds post also includes an open call for insiders, with ShadowByt3$ offering to share proceeds with individuals willing to provide access to organizations. The recruitment effort underscores that the group remains actively engaged in seeking new intrusion opportunities.

At this stage, the Ben Leeds Properties incident remains unconfirmed. The actor has published supporting material and detailed descriptions of the alleged data, but BreachNews has not independently verified the full archive, the claimed Realm-X extraction process or continued access to the AppFolio environment.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site