NAI Earle Furman Data Breach

Alleged

Ransomware claim involving NAI Earle Furman.

Published: Sep 22, 2026 Secp0
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
NAI Earle Furman
Industry
Professional Services
Threat Actor
Secp0
Date of Incident
Sep 22, 2026

Executive Summary

NAI Earle Furman, a professional services firm based in the United States, was listed on the Secp0 ransomware group’s dark web portal on September 22, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring service. The company operates within the commercial real estate sector, offering services such as brokerage, property management, and advisory. The circumstances that might attract ransomware or extortion activity are not detailed, but the nature of commercial real estate services often involves sensitive client data and financial information. This appears to be the sole documented victim claimed by Secp0 within the past 60 days, as identified by SOCRadar. Due to the limited public activity of Secp0, their typical operational profile, targeted tactics, techniques, and procedures (TTPs) cannot be definitively characterized at this time. The group may be newly active, or they might be operating with a low profile, making it difficult to establish patterns based on this single claim. Further monitoring will be necessary to understand their strategic approach to victimology.

Technical Analysis

SOCRadar’s stealer-log telemetry detected a significant exposure related to the naief[.]com domain. Eight records were identified, all linked to a single corporate employee. The credentials associated with this employee were compromised from secure.costargroup[.]com, a Software as a Service (SaaS) platform commonly used in the commercial real estate industry. The harvesting of these credentials occurred over multiple sessions between January 12 and August 11, 2026. Notably, all identified records pertain to corporate access of a third-party service, with no direct records indicating internal infrastructure compromise within this particular data sample. The primary risk profile indicated by this exposure is related to workstation compromise. A critical detail is that the compromised credentials persisted without rotation for a period of seven months. This extended period of unrotated access represents a low-visibility foothold that could be exploited by threat actors, such as ransomware groups, for eventual deployment of malicious payloads. The lack of timely credential rotation is a common precursor to successful ransomware attacks. The queried domain, naief[.]com, is the direct corporate domain for NAI Earle Furman. Therefore, there are no coverage caveats or limitations related to the scope of the stealer-log telemetry query for this specific result. The evidence gathered does not definitively confirm that Secp0 utilized these specific compromised credentials. However, the exposure of corporate account credentials, especially when unrotated and harvested from a widely used third-party platform over an extended duration, presents a significant security risk. Such compromised credentials are often what initial access brokers sell on underground forums. It is therefore prudent to treat the affected employee account as compromised, necessitating immediate credential rotation. Further actions should include pulling access logs from CoStar and any other third-party platforms used by the affected employee during the identified timeframe (January to August 2026) and conducting an investigation of the endpoint for any signs of infostealer activity.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.