
A massive data breach at a California-based real estate firm exposed over 170,000 sensitive records due to a misconfigured and unsecured database, according to a recent report by cybersecurity researcher Jeremiah Fowler published on Website Planet.
The exposed trove—spanning more than 116 gigabytes—belonged to Income Property Investments, a real estate management and investment company operating across the United States. The data, left unencrypted and without password protection, was publicly accessible and contained personally identifiable information (PII) including full names, birthdates, Social Security numbers, physical and email addresses, as well as confidential employment and internal company documents.
Fowler, who discovered the vulnerability during routine internet scans, warned that the information was stored in plaintext, making it highly susceptible to misuse by cybercriminals. “This type of data, when exposed without encryption, provides an open door for identity theft, fraud, or phishing attacks,” he noted.
In his analysis, Fowler detailed the breadth of exposed materials: property inspection reports, eviction notices, demotion and termination letters, petty cash logs, receipts with partial credit card data, internal security and incident reports, medical information, and even police records. Particularly alarming were spreadsheets containing motel employees’ PII, revealing everything from job roles to sensitive personal data.
Fowler emphasized the seriousness of the breach, calling it one of the most revealing and varied datasets he has seen in recent years. While the records clearly pointed to Income Property Investments, it remains unclear whether the database was managed internally or by a third-party vendor.
Upon receiving a responsible disclosure notice, the company reportedly restricted public access to the database the same day. No public statement from Income Property Investments has been released as of this writing.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543