Data Breach & Privacy
Blog > Data Breach & Privacy
Tishman Speyer Data Breach: What Clients Need to Know
Tishman Speyer, a global real estate developer and investment manager, reported that personal information belonging to certain investors was compromised in a third-party vendor data security incident. Here is what the company has disclosed so far and what clients can consider doing.

Who May Be Affected by the Tishman Speyer Breach
Certain investors and clients whose tax files were handled by vendors
Notification letters are being sent directly to individual investors and clients of Tishman Speyer whose personal tax information was handled by Ernst & Young. Because Tishman Speyer is a major global real estate owner and investment firm, the breach impacts individuals who hold investments across its portfolio properties and funds. State regulatory disclosures confirm that at least 24 Massachusetts residents were affected by the incident, though the comprehensive nationwide total of impacted investors has not been publicly released by Tishman Speyer or Ernst & Young.
Under state notification requirements, including California’s data breach notification law under Civil Code § 1798.82, businesses that experience a data security incident impacting more than 500 California residents must submit a formal disclosure and sample letter to the California Attorney General. If widespread investor filings are submitted in California and other states, regulatory records will provide a clearer picture of the incident’s geographic scope. Individuals who invested in Tishman Speyer properties and receive a formal breach notice should verify that their contact details on file are current.
How Tishman Speyer Responded and What Protections Are Offered
Two years of complimentary credit monitoring and dedicated call center
Following the confirmation of unauthorized activity within the third-party IT platform, Ernst & Young took steps to secure the affected environment, terminate unauthorized access, and conduct a forensic examination alongside an independent cybersecurity firm. The firm confirmed that the platform vulnerability was addressed, reviewed the compromised documents to determine which clients and investors were impacted, and notified relevant federal law enforcement authorities. Tishman Speyer coordinated with the vendor once notified in August 2026 to facilitate direct communications to affected investors.
To assist impacted individuals, Ernst & Young is offering 24 months of complimentary credit and identity monitoring services through Experian IdentityWorks for United States residents, including credit reporting, identity restoration support, and insurance coverage. Affected individuals residing outside the United States are being offered 24 months of Cyber Monitoring through Cyberscout, a TransUnion company, with an enrollment window requiring registration within 90 days of receiving the notice. Unique activation codes and deadlines are included in each letter, and Ernst & Young established a dedicated assistance line and email at Privacy.Notification@ey.com to address investor inquiries.
Steps You Can Take to Protect Yourself
Practical actions you can take to safeguard your personal information
If you received a notification indicating that your information was involved in the Tishman Speyer vendor data breach, taking immediate proactive steps can help reduce your vulnerability to fraud:
- Review your notification letter carefully. Check the specific personal data elements listed in your letter and locate your unique activation code and enrollment deadline for credit monitoring services.
- Place a fraud alert or credit freeze with the major credit bureaus. Contact Equifax, Experian, and TransUnion to place a freeze or alert on your credit files to prevent unauthorized accounts from being opened in your name.
- Order and inspect your free annual credit reports. Visit annualcreditreport.com to review your credit files from all three national bureaus for unfamiliar accounts, hard inquiries, or suspicious activity.
- Monitor your financial accounts and billing statements closely. Regularly review your investment statements, bank accounts, and explanation-of-benefits statements for any unauthorized transactions or irregular entries.
- Stay alert to phishing communications referencing the breach. Watch out for suspicious emails, phone calls, or text messages that claim to represent Tishman Speyer, tax authorities, or Ernst & Young asking for sensitive verification details.
This information is a general overview and is not legal advice; your situation may differ, and consulting a legal professional can help you understand rights that may apply to you.
Talk to Wilshire Law Firm
Were you affected by the Tishman Speyer data breach?
If your health information or personal data may have been involved in the Tishman Speyer data breach, do you know what your options are? Our nationally recognized, award-winning team is here to help you understand your rights. Wilshire Law Firm offers free consultations and free case reviews with a legal professional, and we are available 24/7. Because we work on a contingency basis, there are no fees unless you get paid.
Contact Wilshire Law Firm today to schedule your free case review and get your questions answered.
FAQs
The unauthorized access occurred between March 28, 2026, and April 12, 2026, on an IT service platform operated by Ernst & Young, a tax vendor for Tishman Speyer. Ernst & Young confirmed the suspicious activity on April 23, 2026, and notified Tishman Speyer of impacted investor data on August 6, 2026, before completing individual identification on August 25, 2026.
The incident occurred when an unauthorized third party gained access to an external IT service management platform used by Ernst & Young, which provides tax preparation services to Tishman Speyer. The intruder downloaded support documents containing investor tax information. Tishman Speyer reported that its own internal computer networks and servers were not compromised during the incident.
The compromised information includes investor names and Social Security numbers associated with Tishman Speyer investment holdings. According to the breach disclosure, specific data elements vary by individual depending on the support documents involved. The notification confirms that bank account numbers, income details, and investor net worth were not among the compromised records.
The total nationwide number of individuals affected has not been publicly disclosed by Tishman Speyer or Ernst & Young. However, an official filing submitted to the Massachusetts Office of Consumer Affairs and Business Regulation indicates that at least 24 Massachusetts residents were affected by the breach.
Yes, complimentary credit monitoring is being provided on behalf of Tishman Speyer by its vendor, Ernst & Young. Affected United States residents are offered 24 months of credit monitoring and identity restoration through Experian IdentityWorks, while international investors are offered 24 months of Cyber Monitoring via Cyberscout.
If you received a notification letter regarding Tishman Speyer, review the document to identify which personal details were exposed. Enroll in the free credit monitoring service before the stated deadline using your unique code, place fraud alerts or security freezes on your credit files, and carefully monitor your investment accounts for suspicious activity.
Individuals who believe they were affected by the Tishman Speyer incident may have legal options, and data breaches involving sensitive personal information can sometimes lead to class action litigation. Whether a claim may apply to you depends on the specific facts. A free case review with a legal professional can help you understand your potential rights.


What Information May Have Been Involved
Social Security numbers and personally identifiable investor records w
According to the notification letter issued on behalf of Tishman Speyer, the information compromised in the incident includes investor names in combination with one or more sensitive data elements, notably Social Security numbers. The letter clarifies that the specific categories of data involved may vary from person to person depending on the documents included in Ernst & Young’s support tickets. The notice also explicitly confirms that bank account numbers, individual income details, and personal net worth were not among the compromised materials.
Even when a company reports that it is not aware of any actual misuse, the unauthorized exposure of Social Security numbers and personal identifiable information can raise the risk of identity theft, financial fraud, or targeted phishing schemes. When compromised records include government identifiers tied to investment accounts, bad actors can attempt to assemble detailed profiles to exploit other financial relationships. Affected individuals should treat any communication claiming to involve their investments or tax records with heightened scrutiny.