Blog > Data Breach & Privacy

Tishman Speyer Data Breach: What Clients Need to Know

Tishman Speyer, a global real estate developer and investment manager, reported that personal information belonging to certain investors was compromised in a third-party vendor data security incident. Here is what the company has disclosed so far and what clients can consider doing.

Tishman Speyer Data Breach: What Clients Need to Know

What Happened in the Tishman Speyer Data Breach

Unauthorized access to an external tax vendor compromised investor fil

According to a data breach notification filed with the Massachusetts Office of Consumer Affairs and Business Regulation, personal information belonging to Tishman Speyer investors was compromised during a security incident involving Ernst & Young LLP, a third-party accounting firm that provides tax services to the real estate company. Ernst & Young determined that an unauthorized third party accessed a third-party information technology service management platform between March 28, 2026, and April 12, 2026, downloading documents that contained client records. The accounting firm detected the anomalous activity on April 23, 2026, engaged an independent cybersecurity forensics firm to investigate and contain the incident, and notified federal law enforcement. Ernst & Young subsequently alerted Tishman Speyer on August 6, 2026, that investor records were potentially involved, and confirmed the specific affected individuals on August 25, 2026.

The breach occurred entirely within Ernst & Young’s vendor environment, and Tishman Speyer confirmed that its own internal corporate computer networks and systems were not accessed or impacted. While the notification indicates that unauthorized documents were downloaded from the vendor platform, neither company has reported evidence that the stolen investor information has been misused for fraud or identity theft. However, because sensitive records were removed from the vendor platform, affected individuals cannot fully rule out future risks to their personal data.

What Information May Have Been Involved

Social Security numbers and personally identifiable investor records w

According to the notification letter issued on behalf of Tishman Speyer, the information compromised in the incident includes investor names in combination with one or more sensitive data elements, notably Social Security numbers. The letter clarifies that the specific categories of data involved may vary from person to person depending on the documents included in Ernst & Young’s support tickets. The notice also explicitly confirms that bank account numbers, individual income details, and personal net worth were not among the compromised materials.

Even when a company reports that it is not aware of any actual misuse, the unauthorized exposure of Social Security numbers and personal identifiable information can raise the risk of identity theft, financial fraud, or targeted phishing schemes. When compromised records include government identifiers tied to investment accounts, bad actors can attempt to assemble detailed profiles to exploit other financial relationships. Affected individuals should treat any communication claiming to involve their investments or tax records with heightened scrutiny.

Who May Be Affected by the Tishman Speyer Breach

Certain investors and clients whose tax files were handled by vendors

Notification letters are being sent directly to individual investors and clients of Tishman Speyer whose personal tax information was handled by Ernst & Young. Because Tishman Speyer is a major global real estate owner and investment firm, the breach impacts individuals who hold investments across its portfolio properties and funds. State regulatory disclosures confirm that at least 24 Massachusetts residents were affected by the incident, though the comprehensive nationwide total of impacted investors has not been publicly released by Tishman Speyer or Ernst & Young.

Under state notification requirements, including California’s data breach notification law under Civil Code § 1798.82, businesses that experience a data security incident impacting more than 500 California residents must submit a formal disclosure and sample letter to the California Attorney General. If widespread investor filings are submitted in California and other states, regulatory records will provide a clearer picture of the incident’s geographic scope. Individuals who invested in Tishman Speyer properties and receive a formal breach notice should verify that their contact details on file are current.

How Tishman Speyer Responded and What Protections Are Offered

Two years of complimentary credit monitoring and dedicated call center

Following the confirmation of unauthorized activity within the third-party IT platform, Ernst & Young took steps to secure the affected environment, terminate unauthorized access, and conduct a forensic examination alongside an independent cybersecurity firm. The firm confirmed that the platform vulnerability was addressed, reviewed the compromised documents to determine which clients and investors were impacted, and notified relevant federal law enforcement authorities. Tishman Speyer coordinated with the vendor once notified in August 2026 to facilitate direct communications to affected investors.

To assist impacted individuals, Ernst & Young is offering 24 months of complimentary credit and identity monitoring services through Experian IdentityWorks for United States residents, including credit reporting, identity restoration support, and insurance coverage. Affected individuals residing outside the United States are being offered 24 months of Cyber Monitoring through Cyberscout, a TransUnion company, with an enrollment window requiring registration within 90 days of receiving the notice. Unique activation codes and deadlines are included in each letter, and Ernst & Young established a dedicated assistance line and email at Privacy.Notification@ey.com to address investor inquiries.

Steps You Can Take to Protect Yourself

Practical actions you can take to safeguard your personal information

If you received a notification indicating that your information was involved in the Tishman Speyer vendor data breach, taking immediate proactive steps can help reduce your vulnerability to fraud:

  • Review your notification letter carefully. Check the specific personal data elements listed in your letter and locate your unique activation code and enrollment deadline for credit monitoring services.
  • Place a fraud alert or credit freeze with the major credit bureaus. Contact Equifax, Experian, and TransUnion to place a freeze or alert on your credit files to prevent unauthorized accounts from being opened in your name.
  • Order and inspect your free annual credit reports. Visit annualcreditreport.com to review your credit files from all three national bureaus for unfamiliar accounts, hard inquiries, or suspicious activity.
  • Monitor your financial accounts and billing statements closely. Regularly review your investment statements, bank accounts, and explanation-of-benefits statements for any unauthorized transactions or irregular entries.
  • Stay alert to phishing communications referencing the breach. Watch out for suspicious emails, phone calls, or text messages that claim to represent Tishman Speyer, tax authorities, or Ernst & Young asking for sensitive verification details.

This information is a general overview and is not legal advice; your situation may differ, and consulting a legal professional can help you understand rights that may apply to you.

Talk to Wilshire Law Firm

Were you affected by the Tishman Speyer data breach?

If your health information or personal data may have been involved in the Tishman Speyer data breach, do you know what your options are? Our nationally recognized, award-winning team is here to help you understand your rights. Wilshire Law Firm offers free consultations and free case reviews with a legal professional, and we are available 24/7. Because we work on a contingency basis, there are no fees unless you get paid.

Contact Wilshire Law Firm today to schedule your free case review and get your questions answered.

FAQs

The unauthorized access occurred between March 28, 2026, and April 12, 2026, on an IT service platform operated by Ernst & Young, a tax vendor for Tishman Speyer. Ernst & Young confirmed the suspicious activity on April 23, 2026, and notified Tishman Speyer of impacted investor data on August 6, 2026, before completing individual identification on August 25, 2026.

The incident occurred when an unauthorized third party gained access to an external IT service management platform used by Ernst & Young, which provides tax preparation services to Tishman Speyer. The intruder downloaded support documents containing investor tax information. Tishman Speyer reported that its own internal computer networks and servers were not compromised during the incident.

The compromised information includes investor names and Social Security numbers associated with Tishman Speyer investment holdings. According to the breach disclosure, specific data elements vary by individual depending on the support documents involved. The notification confirms that bank account numbers, income details, and investor net worth were not among the compromised records.

The total nationwide number of individuals affected has not been publicly disclosed by Tishman Speyer or Ernst & Young. However, an official filing submitted to the Massachusetts Office of Consumer Affairs and Business Regulation indicates that at least 24 Massachusetts residents were affected by the breach.

Yes, complimentary credit monitoring is being provided on behalf of Tishman Speyer by its vendor, Ernst & Young. Affected United States residents are offered 24 months of credit monitoring and identity restoration through Experian IdentityWorks, while international investors are offered 24 months of Cyber Monitoring via Cyberscout.

If you received a notification letter regarding Tishman Speyer, review the document to identify which personal details were exposed. Enroll in the free credit monitoring service before the stated deadline using your unique code, place fraud alerts or security freezes on your credit files, and carefully monitor your investment accounts for suspicious activity.

Individuals who believe they were affected by the Tishman Speyer incident may have legal options, and data breaches involving sensitive personal information can sometimes lead to class action litigation. Whether a claim may apply to you depends on the specific facts. A free case review with a legal professional can help you understand your potential rights.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,525 reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance