ShadowByt3$ Leaks Alleged HandyTrac Data From Greystar Arizona Property

ShadowByt3$ claims it leaked key control, employee, financial and administrative data tied to a Greystar-managed Arizona apartment property.
ShadowByt3$ post claiming a HandyTrac breach affecting The Retreat at Litchfield Park, a Greystar-managed property in Arizona.
ShadowByt3$ claims it leaked HandyTrac data associated with The Retreat at Litchfield Park after an alleged $10,000 ransom demand went unpaid. The actor claims the exposed material includes key maps, property security information, employee data, vendor records and administrative information. Download links have been redacted by BreachNews.

ShadowByt3$ has published data it claims was stolen through HandyTrac from The Retreat at Litchfield Park, a Greystar-managed apartment community in Arizona, after an earlier $10,000 extortion demand allegedly went unpaid.

The Sept. 19, 2026 release marks an escalation of an extortion claim that first surfaced several days earlier. ShadowByt3$ had previously claimed access to HandyTrac information associated with a Greystar property in Litchfield Park and threatened to release the material if the affected organization did not engage.

The threat actor now claims negotiations did not occur and says it has released the allegedly stolen files.

According to ShadowByt3$, the exposed material includes physical-to-digital key mapping information, property security and vulnerability information, employee and credential data, financial and vendor records, and information associated with administrative functions.

The group specifically identified The Retreat at Litchfield Park and claimed no other HandyTrac customers or Greystar properties were affected by this particular incident.

BreachNews has obtained an archive represented as containing the leaked material. However, BreachNews has not independently authenticated the contents or established that the files were obtained through unauthorized access to HandyTrac or Greystar systems.

Claim centers on physical key management system

The nature of the alleged data makes the incident potentially more sensitive than a conventional property management data breach.

HandyTrac provides electronic key control systems used by multifamily property operators to manage and track physical keys. The company’s systems can record when keys are removed and returned, restrict access to authorized employees and maintain information connecting physical keys with units.

HandyTrac publicly identifies Greystar as a customer and has highlighted the property management company’s use of its key control technology.

According to HandyTrac’s documentation, its current key map is available through its website to authorized users. The company also uses key rotation as a security measure, assigning returned keys to random empty hooks so previously printed key maps become inaccurate as the system is used.

That distinction is important when assessing ShadowByt3$’s claim. Possession of historical key mapping information would not necessarily establish the current physical location of keys inside an actively used HandyTrac cabinet.

However, property-specific access information, employee credentials or current administrative access could carry more significant security implications if the threat actor’s claims prove accurate.

ShadowByt3$ claims $10,000 ransom was rejected

ShadowByt3$ claims it gave the affected organization multiple opportunities to communicate before releasing the data.

In its latest post, the group said it demanded $10,000 and decided to publish the information after allegedly being locked out and receiving no payment.

The HandyTrac claim follows an earlier ShadowByt3$ breach claim involving Ben Leeds Properties, where the threat actor alleged it obtained property management data through AppFolio. That incident also involved information associated with tenants, leasing operations and property maintenance.

The threat actor claims the latest release is limited to The Retreat at Litchfield Park and does not include information belonging to other HandyTrac customers or Greystar properties.

BreachNews has not independently verified the ransom negotiations, whether the threat actor previously maintained administrative access, or its assertion that the exposure is isolated to a single property.

The release itself does not establish whether the initial intrusion occurred through HandyTrac’s central infrastructure, credentials associated with the individual property, a Greystar-managed account or another access point.

Employee and financial records allegedly exposed

Beyond key management information, ShadowByt3$ claims the stolen material includes employee identity and credential information as well as financial and vendor records.

The group specifically described records relating to open and closed invoices and administrative functionality associated with the affected HandyTrac environment.

If authentic, the combination of employee, vendor, financial and property access information could create several different risks. Credentials could potentially be reused to access systems if they remain valid, while vendor and invoice information could provide material for targeted phishing or payment fraud.

Property security information requires particular caution because the alleged victim is a residential community. BreachNews is therefore not publishing or linking to the leaked archive, physical key information, credentials, property vulnerability details or other potentially sensitive material included in the threat actor’s release.

HandyTrac uses rotating key locations

HandyTrac’s own security documentation provides additional context for the claimed key mapping exposure.

The company says keys returned to its systems are assigned to random empty hooks. As a result, printed key maps become inaccurate as keys are used and returned, a design intended to prevent employees or other individuals from memorizing where specific keys are stored.

HandyTrac advises customers that the current key map is available online only to authorized users and says printed maps used during installation should be destroyed after setup.

This means any assessment of the physical-security impact depends heavily on when the allegedly stolen information was generated, whether it remained current and what other administrative information was obtained.

There is currently no evidence available to BreachNews establishing that ShadowByt3$ obtained physical apartment keys or gained physical access to residences.

Scope remains unconfirmed

Public reporting on the initial ShadowByt3$ listing described the incident as an unverified extortion claim, with no confirmation from HandyTrac or Greystar establishing the attack’s scope.

The Sept. 19 publication increases the seriousness of the claim because ShadowByt3$ is now purporting to release the information it previously threatened to expose. It does not, by itself, establish how the information was obtained or authenticate every claim made by the threat actor.

HandyTrac had not issued any public statement confirming the alleged breach at time of publication. BreachNews also found no public statement from Greystar confirming that The Retreat at Litchfield Park was compromised.

The key question now is whether the affected organizations determine that the allegedly exposed key control and administrative information was current and whether any credentials or physical access information require rotation or replacement.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site