Ransomware group coinbasecartel hits Colliers Real Estate
Colliers Real Estate — a business services target operating in US has been listed by the coinbasecartel ransomware group on 2026-07-20. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | Colliers Real Estate |
|---|---|
| Threat Group | coinbasecartel |
| Summary | [AI generated] Colliers International is a global commercial real estate services company headquartered in Toronto, Canada. It operates across more than 60 countries, offering services including property management, investment sales, leasing, valuation, and advisory. The firm serves corporate, institutional, and private clients across office, industrial, retail, and residential property sectors, making it one of the largest real estate services firms worldwide. |
| Date of Breach | 2026-07-20 |
| Discovery Date | 2026-07-20 |
| Region | US |
| Target Domain | — |
| Business Sector | Business Services |
| Severity | MEDIUM |
Claim by coinbasecartel
[AI generated] Colliers International is a global commercial real estate services company headquartered in Toronto, Canada. It operates across more than 60 countries, offering services including property management, investment sales, leasing, valuation, and advisory. The firm serves corporate, institutional, and private clients across office, industrial, retail, and residential property sectors, making it one of the largest real estate services firms worldwide.
Posted by the coinbasecartel threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Leak post (onion / Tor)
http://fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion/companies/colliers
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

