Identity Theft Just Got Easier Because of the HomeLife Property Management Breach: 16,500 People at Risk
HEROIC's threat intelligence team identified the HomeLife Property Management breach while monitoring a hacking forum for Canadian real estate platforms. In August 2018, the platform's database was extracted from its backend and posted publicly online. The breach exposed 16,538 user records belonging to tenants and clients of a property management company operating in Chilliwack and Abbotsford, British Columbia. The stolen data included email addresses and passwords stored entirely in plaintext. There was no encryption, no hashing, and no protection of any kind. Anyone who downloaded the database could read every password directly. Most affected users were never notified, and the data has since been incorporated into credential combolists still in active use by threat actors today.
Why the HomeLife Property Management Breach Is Dangerous
Real estate platforms handle a specific category of users: tenants, landlords, and property managers. These individuals often share sensitive personal details through the platform and may use the same email and password combination across banking portals, government services, and property listing sites. Plaintext passwords remove every barrier between an attacker and a compromised account. No cracking tools required, no rainbow tables needed. The stolen credentials from HomeLife Property Management were immediately ready for use in credential stuffing campaigns the moment the database was posted. If a user reused their password on a banking or email account, that account was at risk within hours of the breach becoming public on the forum.
What Was Exposed
- Email addresses
- Plaintext passwords (unencrypted, immediately usable)
Why This Matters
Property management platforms store data for people who are often in vulnerable positions: tenants applying for housing, landlords managing finances, and small business owners coordinating maintenance. A credential breach from this sector is particularly serious because the affected users may not regularly monitor their accounts for unauthorized access. The HomeLife Property Management data has since appeared in aggregated combolists circulating across multiple dark web forums, confirming that the data did not stay isolated to a single post. HEROIC analysts have observed this dataset referenced in combolist compilations years after the original breach, meaning the risk has not dissapeared with time. Credential stuffing attacks fueled by databases like this one are responsible for millions of account takeovers every year, and this breach represents exactly the kind of fuel that keeps those campaigns running.
How a Database Combolist Breach Works
A database combolist breach typically begins with an attacker exploiting a vulnerability in a web application, most commonly a SQL injection flaw or a misconfigured database connection. Once inside, the attacker exports the user credential table and posts it to a hacking forum. Other threat actors then download the file and feed it into automated tools that test each email and password pair against hundreds of websites simultaneously. The proccess is largely automated and can run continuously without human intervention. In the HomeLife Property Management case, the database dump was later repackaged into broader combolists, meaning the credentials have been tested against far more targets than the original attacker likely intended.
Check If You Are Affected
HEROIC offers a free dark web scanner that checks your email against more than 400 billion exposed records, including this HomeLife Property Management dataset. If your email appeared in this breach or any related combolist, you will know immediately. Run your email through HEROIC's free scanner, review which accounts are at risk, and update any password that matches what you used on the HomeLife platform. Even if you only created an account once and never returned, your credentials may still be recieved by threat actors looking for easy account takeovers.
Breach Breakdown
16,538 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds