Skip to content
       

Blog

Property Management Data Security: Why the Sector Is a Target and What Governance Requires

Property Management Data Security: Why the Sector Is a Target and What Governance Requires

A property company holds a combination of data that few other businesses do. Social Security numbers from screening. Bank details for ACH. Employment and income documentation. Copies of identity documents. Access credentials, sometimes biometric. Camera footage. And, in a literal sense, the keys to where people sleep.

Most of it sits across a dozen or more separate systems run by a dozen or more separate companies.

This article is about the risks specific to that shape of business and the governance decisions that address them. It does not cover platform security controls. Encryption, role-based access, audit trails, and certification frameworks are covered in RIOO's guide to security, compliance, and data privacy in property management systems.

Key takeaways

  • The risk is not that property companies are careless. It is that they hold unusually complete identity data across an unusually fragmented vendor stack.

  • Third-party breach is the exposure operators most often underestimate. Your posture can be sound and your data still leak.

  • Seasonal leasing turnover and field staff on personal devices create access control gaps that are structural, not accidental.

  • Wire fraud targeting deposits, owner distributions, and reserve transfers is among the most common claims in the sector.

  • Retention is among the cheapest controls available and the one almost nobody has decided.

In this guide

  • Why are property companies targeted?

  • The two routes in

  • The risk factors specific to property operations

  • How do you manage third-party vendor risk?

  • Common security mistakes in property management

  • Wire fraud and voice impersonation

  • Data governance: retention, deletion, and ownership

  • What happens when a management contract transfers

  • How should a property company prepare for a breach?

  • What to ask before adding a proptech vendor

  • Frequently asked questions

Why are property companies targeted?

Short answer: Because the data is unusually complete and the systems are unusually connected. A rental application alone yields a Social Security number, employment history, bank account details, and current and prior addresses. Add payment records, identity documents, and access credentials, and a single tenant file contains most of what identity fraud requires. Property platforms then connect leasing, accounting, maintenance, and communication, so one weak point can reach a great deal at once.

Analysis of breaches in the sector identifies the same drivers repeatedly: a high volume of sensitive data collected to process applications and payments, complex interconnected systems where a single weak point exposes large volumes, third-party vendors handling maintenance, payments, and screening with access to company data, evolving state breach-notification obligations, and the financial fraud opportunity created by high-value transactions.

The second factor deserves emphasis. In most industries the crown-jewel data sits in one system that can be hardened. In property management it is distributed by design across the platforms that make operations work.

The two routes in

Two publicly reported incidents from 2026 illustrate how this actually happens, and the contrast between them is the useful part.

In the first, a real estate firm disclosed to six state attorneys general beginning in February that a software vulnerability had exposed Social Security numbers and other personal information belonging to roughly 17,000 individuals. The company contained the incident, worked with its platform provider and external cybersecurity experts, applied security patches, and offered 24 months of credit monitoring and identity protection to those affected.

In the second, a global commercial real estate services firm confirmed a data security incident in early May traced to vishing, or voice phishing, where a person is tricked over the phone into sharing credentials or access codes. Two criminal groups claimed related activity within days of each other, one of them claiming more than 500,000 records containing personally identifiable information and internal corporate data.

The first required a software flaw. The second did not. Both organisations responded and disclosed appropriately, and the point is not their security posture. It is that social engineering is currently the more productive route, and no amount of platform hardening addresses it.

The risk factors specific to property operations

Generic security advice misses what makes this sector distinct. Five things do.

Risk factor

Why property operations create it

Seasonal access churn

Leasing staff turn over on a seasonal cycle, so users are onboarded and offboarded constantly, often without consistent access control or security training

Field staff on personal devices

Maintenance and site teams routinely access property systems from personal phones, creating shadow IT that cannot be monitored or protected

High-value transaction volume

Deposits, owner distributions, reserve transfers, and vendor payments move regularly and in size, which is what business email compromise targets

Distributed operations, lean IT

Sites are geographically spread and IT teams are small, so consistent control application is genuinely hard

Operational dependency on one system

If the property platform goes down, rent collection, maintenance coordination, and owner reporting stop, which is why ransomware pricing in this sector is aggressive

The first two are worth acting on first, because they are structural rather than incidental. Sector analysis makes the same point: seasonal turnover in leasing staff means new users are regularly onboarded and offboarded, often without consistent access controls or security training, while maintenance and field staff frequently use personal devices to access property systems, creating shadow IT that security teams cannot monitor or protect.

A property company will always have seasonal leasing churn and field staff who need system access from wherever they are standing. The control has to fit that reality rather than assume it away.

Two questions worth answering this week: how long after a leasing agent leaves does their access actually get revoked, and what happens to property data on a maintenance technician's personal phone when they resign.

How do you manage third-party vendor risk?

Short answer: By knowing which vendors hold which categories of data, contracting for breach notification and certified deletion, and treating vendor selection as a security decision rather than a procurement one. This is the exposure operators most often underestimate, because it is the one their own security programme cannot fix.

A working property stack typically includes a management platform, an accounting system, a screening provider, a payments processor, a maintenance or work order system, a listing syndication tool, an e-signature provider, an access control system, and often building automation, cameras, and IoT sensors. Each holds or can reach some portion of tenant or financial data. Each is an independent breach surface.

Vendor category

Data it typically holds

Tenant screening

SSN, credit file, employment and income, prior addresses

Payments processing

Bank account and card details, transaction history

Leasing and e-signature

Executed leases, identity documents, signatures

Maintenance systems

Unit access notes, occupant contact details, entry records

Access control

Credentials, entry logs, sometimes biometric templates

Cameras and IoT

Footage and occupancy data from common and private areas

Accounting

Owner banking details, vendor payment records

A breach at any one of these can expose tenant data even where the property company's own posture is sound. The practical implication is that the integration and data exchange design between systems is part of the attack surface rather than separate from it.

It is also an argument for consolidation on its own terms. Fewer systems holding the same data means fewer independent breach surfaces, fewer data processing agreements to maintain, and fewer offboarding exercises to get right. That is one of the less-discussed cases for running property operations from a single connected platform.

Common security mistakes in property management

Five patterns that show up repeatedly, none of which involve anyone doing anything obviously wrong.

Mistake

What it actually costs

Treating offboarding as an HR task

Departed leasing agents retain platform access for weeks, sometimes permanently, because nobody owns revocation

Keeping applicant files indefinitely

A rejected applicant's SSN and credit report sit in the system for years with no operational purpose and full breach exposure

Assuming vendor security is the vendor's problem

A breach at a screening provider exposes your residents, and the notification obligation is still yours

Verifying payment changes by replying to the request

Reply-based verification confirms nothing, since the attacker controls the thread

Having no manual fallback

When the platform is unavailable, rent collection and emergency dispatch stop, which is precisely what makes ransomware profitable here

The pattern connecting them is that each is a reasonable default that stops being reasonable at scale. Offboarding is fine when three people leave a year. Keeping applicant files is fine when there are forty of them. The controls that fail are the ones that were never designed, only inherited.

Wire fraud and voice impersonation

Property management runs on regular high-value transfers: security deposits, owner distributions, association reserve movements, vendor payments, and transaction proceeds. Business email compromise targeting those flows is among the most common cyber claims in the sector. A fraudulent message impersonating an owner, vendor, or title company requesting changed wire instructions can move money before anyone notices.

The impersonation is getting harder to detect. RSM reports encountering situations where individuals received voicemails or messages closely mimicking the voices of a CEO or CFO, requesting urgent wire transfers or similar actions, and notes this is forcing companies to rethink verification procedures.

The defence is procedural rather than technical:

  • Out-of-band verification for any change to payment instructions, using a number already on file rather than one supplied in the request.

  • A dual approval threshold above which no transfer proceeds on one person's authority.

  • A stated policy that urgency is never a reason to skip verification, communicated widely enough that a junior staff member feels able to slow down a request that appears to come from an executive.

  • A named verification contact per owner and per major vendor, established at onboarding rather than at the moment of a suspicious request.

Voice familiarity is no longer evidence of identity. Any procedure that relies on recognising someone needs replacing.

Data governance: retention, deletion, and ownership

Security controls limit who can reach data. Governance limits what data exists to be reached, and it is the cheaper of the two.

Three questions most property companies have not formally answered:

How long do you keep a rejected applicant's file? That file contains a Social Security number, a credit report, and income documentation for someone who never became a customer. Retention obligations vary widely. Some regimes require holding applicant records for two to three years, particularly where fair housing or programme compliance applies. Others require deletion considerably sooner. The failure mode is not choosing wrong, it is never choosing, so files accumulate indefinitely by default.

What happens on a deletion request? Where privacy regimes grant deletion rights, the request has to reach every system holding a copy, including the ones a vendor operates. If you cannot enumerate which vendors hold a given tenant's data, you cannot honour the request.

What is deleted at vendor offboarding? When you stop using a screening provider or a payments processor, their copy of your tenant data does not disappear automatically. Deletion and certification of deletion is a contract term, and it needs to be in the contract before the relationship ends rather than negotiated during the exit.

Governance artefact

What it prevents

Retention schedule by record type

Indefinite accumulation of applicant PII

Data inventory naming every vendor per data category

Inability to honour deletion or notify on breach

Deletion clause in every vendor contract

Data persisting at former vendors

Access review on a fixed cycle

Departed staff retaining credentials

Documented lawful basis per processing activity

Regulatory exposure under privacy regimes

What happens when a management contract transfers

Rarely discussed and consistently messy.

When a management contract moves to a new manager, or an asset is sold, tenant data has to move with it. Several questions become live at once: who is the controller of that data and who is the processor, what may lawfully transfer, what must the outgoing manager delete, what happens to accounts in the outgoing manager's systems, and who tells the residents.

Handled well, this is an orderly transfer with a documented scope and a deletion certificate. Handled badly, and it usually is, the outgoing manager retains a full copy of resident data for a portfolio they no longer manage, indefinitely, in a system nobody is watching.

Address it in the management agreement, at the point where you have leverage, rather than during the transition.

How should a property company prepare for a breach?

Short answer: By planning for a response where the affected population is your residents rather than your business customers. That means statutory notification timelines, a resident communication plan, and a way to keep collecting rent and dispatching emergency maintenance while systems are unavailable.

  • Notification obligations are statutory in most jurisdictions, with defined timelines, and they are triggered by specific data categories rather than by your assessment of severity.

  • The affected population is reachable and concentrated. Residents talk to each other, and they live in buildings you operate. Communication failures compound quickly.

  • Operational continuity is part of the response. RSM frames cyber resilience in real estate as the ability to run financial transactions and maintain property operations and tenant services even when technology is disrupted, protecting cash flow, tenant experience and asset value so that a single incident does not stall leasing, rent collection or building operations.

  • Manual fallback matters. If the platform is unavailable for a week, how does rent get collected and how does an emergency work order reach a technician? Answering that is part of the plan, not a separate business continuity exercise.

  • Cyber insurance covers a defined set of costs, including forensic investigation, legal counsel on notification obligations, and business interruption during recovery. Worth reviewing what the policy actually covers against the scenarios above.

What to ask before adding a proptech vendor

  1. What tenant or financial data will you hold or be able to reach? Get it as a list, not a category.

  2. Where is it stored, and in which jurisdictions?

  3. What is your breach notification commitment to us, and in what timeframe?

  4. What is your subprocessor list, and how are we notified when it changes?

  5. What happens to our data at termination, on what timeline, and will you certify deletion?

  6. Can we export our data in a usable format, at any time, without a fee?

  7. What is your patch cadence, and how are customers told about security-relevant updates?

  8. What access will your support staff have to our production data, and is it logged?

The last one gets least attention and matters most. A vendor whose support team can view any tenant record without a logged, justified access request has extended your breach surface to their staffing decisions.

Frequently asked questions

1. Why are property management companies targeted by cybercriminals?
Because they hold unusually complete identity data, including Social Security numbers, bank details, employment history, and identity documents, across interconnected systems where one weak point can reach a large volume. High-value transaction flows add a financial fraud motive on top of the data value.

2. What tenant data is most at risk?
Screening data is the highest value, since it combines Social Security number, credit file, employment and income, and address history in one record. Payment details, identity document copies, and access credentials follow.

3. What is third-party vendor risk in property management?
The exposure created by the screening providers, payment processors, maintenance systems, access control platforms, and other vendors that hold or can reach your tenant data. A breach at any of them can expose that data even when your own security posture is sound.

4. How long should you keep rejected rental applications?
It varies. Some regimes require two to three years, particularly where fair housing or programme compliance applies, while others require deletion sooner. The governance principle is to set a documented schedule by record type and delete on it, because files held with no requirement and no operational purpose are exposure for nothing. Confirm the applicable period for your jurisdictions.

5. What is business email compromise in a property context?
A fraudulent request, typically impersonating an owner, vendor, or title company, asking for a change to payment or wire instructions. It targets deposits, owner distributions, reserve transfers, and vendor payments, and is among the most common cyber claims in the sector.

6. How do you defend against voice impersonation attacks?
Procedurally. Verify any change to payment instructions out of band using a contact already on file, require dual approval above a threshold, establish named verification contacts at onboarding, and make it explicit that urgency never justifies skipping verification.

7. What happens to tenant data when a management contract transfers?
It has to move to the incoming manager, and the outgoing manager's copies have to be dealt with. Scope, controller and processor roles, deletion obligations, and resident communication should be settled in the management agreement rather than during the transition.

8. What should be in a proptech vendor security review?
The specific data the vendor will hold, storage jurisdictions, breach notification commitments and timeframes, the subprocessor list and change notification, deletion terms at termination, data export rights, patch cadence, and what access vendor support staff have to production data.

9. Does consolidating systems improve security?
It reduces the number of independent breach surfaces, data processing agreements, and offboarding exercises. That is a genuine benefit, though it concentrates dependency, which is why continuity planning matters more as consolidation increases.

10. What are the biggest access control gaps in property operations?
Seasonal leasing turnover producing constant onboarding and offboarding without consistent control, and field staff accessing systems from personal devices that cannot be monitored. Both are structural to how property operations work, so controls have to accommodate them rather than assume them away.

Property companies rarely have a security problem because someone was careless. They have one because the business model requires collecting complete identity data from every applicant, sharing it with specialist vendors to do useful work, and granting system access to a workforce that turns over seasonally and operates from wherever the work is.

None of that is going to change. What can change is how much data exists past the point it is needed, how many vendors hold a copy, and whether anyone could produce a list of them on request.

This article provides general information and is not legal advice. Data protection, retention, and breach notification obligations vary by jurisdiction. Confirm the requirements applicable to your operations with qualified counsel.