In February 2026, Castle Group, a US-based real estate firm, was targeted in a ransomware attack. The Qilin group announced the incident on their leak site on February 17, 2026, threatening to release sensitive data unless contacted. This information was reported by cybersecurity news outlets monitoring ransomware activities. No official statements, regulatory filings, or victim notices from Castle Group have been reported.
The specific types of data exposed have not been publicly detailed, though the Qilin group claims to have obtained sensitive information. The number of individuals affected has not been specified in available reports, and it is unclear if SSN, medical, or financial data were involved. The incident is generally linked to Castle Group's US operations, but no specific states have been confirmed as affected.
Details can emerge weeks after an initial disclosure, and notifications may not be immediate, so monitoring for updates can help clarify whether you may be impacted.