Data Breach & Privacy
Blog > Data Breach & Privacy
Millennium Partners Data Breach: What Customers and Employees Need to Know
Millennium Partners Management, a New York-based real estate development firm, reported that an unauthorized party accessed its network in late April 2026 and acquired personal information that may have included Social Security numbers. Here is what the company disclosed and what affected individuals can consider doing.

What Happened in the Millennium Partners Data Breach
A network disruption discovered in April 2026
According to a Notice of Data Security Incident that Millennium Partners Management LLC issued on September 16, 2026, the company discovered a network disruption on April 27, 2026. Millennium reports that its investigation determined an unauthorized party had accessed its network between April 24, 2026, and April 26, 2026, and that on July 9, 2026, the company confirmed personal information from its network had been accessed and acquired.
The company states that upon becoming aware of the disruption it took immediate steps to secure its systems, engaged outside cybersecurity specialists, and enhanced its security posture. Millennium’s notice does not describe how the unauthorized party gained access or how many individuals were involved. Separately, a ransomware group calling itself The Gentlemen is reported to have claimed responsibility for an attack on Millennium Partners in early May 2026; that claim comes from the group’s own leak-site posting, and Millennium has not publicly attributed the incident to any group or confirmed the claim. Public notice came roughly five months after discovery and about two months after the company confirmed data had been taken.
Who May Be Affected by the Millennium Partners Breach
Customers and employees of the real estate firm
Millennium Partners Management is a New York-based developer known for luxury mixed-use and residential real estate projects. The company states that the incident involved the personal information of some of its customers and employees, a group that may include residents or purchasers in its properties as well as current and former staff, though the notice does not break down the affected population further.
Millennium has not published the total number of individuals affected, and as of this writing the incident does not appear on the public breach lists maintained by the California or Vermont attorneys general. If you received a letter from Millennium Partners Management referencing this incident, that notice may indicate your information was among the data reported to have been accessed and acquired.
How Millennium Partners Responded and What Protections Are Offered
Security measures, but no monitoring service described in the public notice
Millennium reports that it secured its systems, brought in outside cybersecurity specialists, and enhanced its security posture following the incident, and that it established a call center to answer questions from affected individuals.
The company’s public notice does not describe an offer of complimentary credit monitoring or identity protection services. Instead, it encourages individuals to review their account statements and credit reports for suspicious activity and errors, and notes that free annual credit reports are available from the three nationwide credit bureaus. If your individual letter includes an offer of monitoring services or an enrollment deadline, follow the instructions in that letter.
Talk to Wilshire Law Firm
Were you affected by the Millennium Partners data breach?
If your personal information may have been involved in the Millennium Partners data breach, do you know what your options are? Our nationally recognized, award-winning team is here to help you understand your rights. Wilshire Law Firm offers free consultations and free case reviews with a legal professional, and we are available 24/7. Because we work on a contingency basis, there are no fees unless you get paid.
Contact Wilshire Law Firm today to schedule your free case review and get your questions answered.
FAQs
According to the company’s notice, unauthorized access to its network occurred between April 24 and April 26, 2026. Millennium discovered a network disruption on April 27, 2026, confirmed on July 9, 2026 that personal information had been accessed and acquired, and issued its public notice on September 16, 2026.
Millennium’s notice says an unauthorized party accessed its network but does not describe the method. A ransomware group known as The Gentlemen is reported to have claimed responsibility in May 2026; the company has not confirmed that claim or named any group.
Millennium states the information accessed and acquired may have included Social Security numbers. The public notice does not itemize other categories; individual letters may describe additional information specific to each recipient.
The company states the incident involved the personal information of some of its customers and employees. It has not published a total number of affected individuals.
The company’s public notice does not describe an offer of credit monitoring or identity protection services; it encourages individuals to review their statements and credit reports and notes that free annual credit reports are available. Check your own letter, which may contain additional terms.
Consider placing a credit freeze or fraud alert, reviewing your credit reports and financial accounts, keeping the letter, and staying alert to phishing. You may also wish to speak with a legal professional about any rights or options that may apply to your situation.
Individuals who believe they were affected may have legal options, and data breaches involving Social Security numbers, particularly where public notice followed months after discovery and no monitoring was offered, can sometimes lead to class action litigation. Whether a claim may apply to you depends on the specific facts. A free case review with a legal professional can help you understand your potential rights.


What Information May Have Been Involved
Social Security numbers among the data that may have been acquired
In its notice, Millennium states that the personal information accessed and acquired may have included Social Security numbers. The notice does not itemize other categories, so exactly which information was involved for any given individual has not been publicly detailed, and it may vary from person to person. Individual notification letters may describe the specific information that applied to each recipient.
Because Social Security numbers are among the data the company identifies, affected individuals may face an elevated risk of identity theft and new-account fraud. Millennium’s public notice does not include a statement about whether any misuse of the information has been detected.