In 2025, AppFolio, Inc. experienced a data breach involving unauthorized access to its hosted CRM system, which occurred between August 8 and August 18, 2025. The company was notified of the incident on August 22, 2025. AppFolio subsequently disabled integrations with Salesloft, the vendor involved, and began mailing notifications to affected individuals on October 6, 2025. These details were confirmed through various state Attorney General filings.
Confirmed data types exposed in the breach include names and Social Security numbers, as explicitly stated in official notices. Class-action and investigative summaries also indicate that addresses and dates of birth may have been exposed. While specific counts for Iowa (799 residents) and Maine (148 residents) are documented, a definitive total number of individuals affected company-wide has not been publicly confirmed, though sources indicate "tens of thousands" or "approximately 0.13% of records accessed." There is no confirmed information regarding the exposure of medical or financial data.
It is important to note that full details of data breaches can emerge over time, and notifications to consumers may be delayed.