Luxury Real Estate Firm Investigates Cyber Attack

Luxury real estate firm New Zealand Sotheby’s International Realty is investigating a cyber security breach involving unauthorized access to a third-party software platform, according to an official company statement. The incident exposed limited contact details, prompting an ongoing forensic investigation and notifications to the National Cyber Security Centre and the Office of the Privacy Commissioner.

Third-Party CRM Software Breach Exposes Client Contact Data

The cyber-attack targeted a Customer Relationship Management (CRM) system used by New Zealand Sotheby’s International Realty (NZSIR) for marketing and operational purposes. According to the firm’s published statements, the unauthorized access compromised specific fields containing names, physical addresses, phone numbers, and email addresses. However, the company confirmed that the compromised platform does not house customer financial transactions. Furthermore, NZSIR stated that threat actors did not access any email exchanges, property documentation, or substantive material related to real estate listings.

Disputed Contact Numbers and Forensic Findings

While the threat actor publicly claimed to have seized 1.6 million contacts during the cyber-attack, NZSIR strongly refuted the figure. Third-party platform forensic investigators assisting with the incident advised that the 1.6 million figure stems entirely from duplicate entries within the system rather than unique client records.

In addition to standard contact fields, NZSIR disclosed in direct emails to affected clients that certain open-text notes fields within the CRM might contain sensitive information that was accessed. The firm stated that individuals impacted by this specific exposure will be contacted directly regarding the contents of those notes.

Containment Steps and Regulatory Notification

Managing director Mark Harris stated that the firm took immediate steps to contain the breach upon discovery and engaged independent cyber security specialists to handle the forensic review. According to NZSIR, the organization regularly reviews its security controls as part of standard operating procedure. Client notifications regarding the breach began on Monday, accompanied by formal precautionary notifications sent to both the National Cyber Security Centre and the Office of the Privacy Commissioner.

Frequently Asked Questions

What data was accessed in the New Zealand Sotheby’s International Realty incident?

According to NZSIR statements, the unauthorized access affected limited contact information including names, addresses, phone numbers, and email addresses stored in a third-party CRM platform, along with potential text notes.

Sotheby's International says it is investigating a cyber security incident. Photo / 123rf
Photo: nzherald.co.nz

Were property transactions or financial accounts compromised?

No. The company confirmed that the third-party platform is not used for customer financial transactions, and no property documentation, emails, or substantive listing materials were accessed.

How many contacts were actually stolen?

While an external threat actor claimed to have obtained 1.6 million contacts, NZSIR refuted this number based on forensic analysis showing the figure represents duplicate database entries.

Stay Informed on Industry Security Updates

Subscribe to our newsletter for verified updates on corporate cyber security developments and real estate market news.

How This Fake Realtor Sold Luxury Apartments She Doesn't Own | TSR Investigates

Leave a Comment