Company Details
cbrealty
44,752
148,870
None
coldwellbankerhomes.com
0
COL_1161607
In-progress


Coldwell Banker Realty Vendor Cyber Rating & Cyber Score
coldwellbankerhomes.comColdwell Banker Realty is one of the nation’s largest real estate brokerages operating in 50 markets in the United States. Powered by a network of approximately 55,000 independent real estate agents and 600 offices, Coldwell Banker Realty, a subsidiary of Anywhere Real Estate Inc. (NYSE:HOUS), operates the company-owned real estate brokerage offices that are part of the worldwide Coldwell Banker Real Estate LLC brand. For more information, visit www.ColdwellBankerHomes.com.
Company Details
cbrealty
44,752
148,870
None
coldwellbankerhomes.com
0
COL_1161607
In-progress
Between 750 and 799

CBR Global Score (TPRM)XXXX

Description: Substack Discloses 2025 Data Breach Exposing User Email Addresses and Phone Numbers Substack has notified select users that their email addresses and phone numbers were exposed in a security incident last October. In an email sent to affected account holders, CEO Chris Best confirmed that an unauthorized third party accessed internal data on February 3, 2025, though passwords, credit card details, and financial information remained secure. The breach involved email addresses, phone numbers, and internal metadata, but Substack stated there is no evidence the data has been misused. The company has since patched the vulnerability and is conducting a full investigation while strengthening its security measures to prevent future incidents. No details were provided on the root cause of the breach or the total number of impacted users. Best apologized for the incident, acknowledging the company’s failure to adequately protect user data. Substack has not yet responded to requests for further clarification on the scope of the breach.
Description: Anywhere Real Estate Hit by Clop Ransomware Attack, Exposing 17,429 Customers In August, Anywhere Real Estate disclosed a data breach affecting 17,429 customers, following an attack by the Clop ransomware gang. The cybercriminals infiltrated the company’s Oracle E-Business Suite environment, accessing and potentially exfiltrating sensitive customer data. A breach notification filed with the Maine Attorney General’s Office confirmed the incident, though details on the exact nature of the compromised information remain limited. Clop, a well-known ransomware and extortion group, has been linked to multiple high-profile attacks, often targeting vulnerabilities in enterprise software. The breach at Anywhere Real Estate parent company of brands like Coldwell Banker, Century 21, and Sotheby’s International Realty highlights the growing threat to real estate and mortgage sectors, where vast amounts of personal and financial data are stored. The company has since notified impacted individuals, but the full scope of the breach’s consequences including potential identity theft or fraud remains unclear. This incident follows a broader trend of cyberattacks on real estate firms, underscoring the industry’s vulnerability to sophisticated ransomware operations.


No incidents recorded for Coldwell Banker Realty in 2026.
No incidents recorded for Coldwell Banker Realty in 2026.
No incidents recorded for Coldwell Banker Realty in 2026.
CBR cyber incidents detection timeline including parent company and subsidiaries

Coldwell Banker Realty is one of the nation’s largest real estate brokerages operating in 50 markets in the United States. Powered by a network of approximately 55,000 independent real estate agents and 600 offices, Coldwell Banker Realty, a subsidiary of Anywhere Real Estate Inc. (NYSE:HOUS), operates the company-owned real estate brokerage offices that are part of the worldwide Coldwell Banker Real Estate LLC brand. For more information, visit www.ColdwellBankerHomes.com.


We’re a leading professional services firm that specializes in real estate and investment management. JLL shapes the future of real estate for a better world by using the most advanced technology to create rewarding opportunities, amazing spaces and sustainable real estate solutions for our clients,

CoStar Group (NASDAQ: CSGP) is a global leader in commercial real estate information, analytics, online marketplaces, and 3D digital twin technology. Founded in 1986, CoStar Group is dedicated to digitizing the world’s real estate, empowering all people to discover properties, insights, and connecti

MEB’S ability to create value for both clients and residents has been the cornerstone of our success. Scott, Libby, Mark, and Jodi have been active in the real estate management industry and have over 125 years of combined experience. With their breadth and depth of knowledge, MEB is the “go-to” co
As one of the leading global real estate franchisors, RE/MAX, LLC is a subsidiary of RE/MAX Holdings (NYSE: RMAX) with more than 140,000 agents in almost 9,000 offices and a presence in more than 110 countries and territories. Nobody in the world sells more real estate than RE/MAX, as measured by

We are a global diversified professional services and investment management company operating through three industry-leading businesses: Commercial Real Estate, Engineering, and Investment Management. With greater than a 30-year track record of consistent growth and strong recurring cash flows, we s

Shimao Group has entered the real estate industry since 1989, After more than 30 years of development, the Group has made its layout in more than 100 core development cities across China, involving real estate, commercial, property management, hotel, theme entertainment and culture. Following the n
Welcome to Coldwell Banker Real Estate LLC, a company founded in 1906 on a commitment to professionalism and customer service which remains the cornerstone of our business philosophy today. We are the nation’s oldest real estate company and our experience has helped make the dream of homeownership a

The SM Group of companies stands today as an institution, a store, a mall, a bank, a home, a resort, a hotel, and a place to see and experience with the family. One of the core business areas of the SM Group is the Shopping Center Management Corporation, generally referred to as SM Supermalls. The

Austin, Texas-based Keller Williams, the world’s largest real estate franchise by agent count, has more than 1,100 offices and 176,000 agents. The franchise is also No. 1 in units and sales volume in the United States. Since 1983, the company has cultivated an agent-centric, technology-driven, and
.png)
Kamini Lane, Coldwell Banker Realty CEO, joins 'The Exchange' to discuss the macro trends impacting homebuyers, recent all-cash deals and...
Coldwell Banker Realty (COMP) announced that Pettingell Professionals — led by Roger Pettingell and Thomas Arbuckle — recorded more than...
H.O. Brittingham Elementary School's Guys with Ties group welcomed ethical hacker Christopher Neuwirth Jan. 16 as a keynote speaker for an...
Coldwell Banker Real Estate LLC today announced the 2025 recipients of its annual year-end awards, recognizing top‑ranking performers whose...
COLUMBUS, Ohio — As more Ohio families add smart technology such as video doorbells and Wi-Fi thermostats to their homes, cybersecurity...
This annual recognition celebrates the achievements of Coldwell Banker-affiliated real estate professionals under the age of 30 who have demonstrated...
Coldwell Banker Real Estate LLC, an Anywhere® (NYSE: HOUS) brand, today announced the recipients of its prestigious 2024 year-end awards.
Nearly 20 local town managers, public works administrators and water plant operators participated in Need to Know: Water Essentials, a workshop held May 3.
In a year when the real estate industry felt under attack from all sides, hackers decided to pile on, disrupting closings, listings and mortgages.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Coldwell Banker Realty is http://www.coldwellbankerhomes.com.
According to Rankiteo, Coldwell Banker Realty’s AI-generated cybersecurity score is 788, reflecting their Fair security posture.
According to Rankiteo, Coldwell Banker Realty currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Coldwell Banker Realty has been affected by multiple supply chain cyber incidents. The affected supply chain sources and their corresponding incident IDs are:
According to Rankiteo, Coldwell Banker Realty is not certified under SOC 2 Type 1.
According to Rankiteo, Coldwell Banker Realty does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Coldwell Banker Realty is not listed as GDPR compliant.
According to Rankiteo, Coldwell Banker Realty does not currently maintain PCI DSS compliance.
According to Rankiteo, Coldwell Banker Realty is not compliant with HIPAA regulations.
According to Rankiteo,Coldwell Banker Realty is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Coldwell Banker Realty operates primarily in the Real Estate industry.
Coldwell Banker Realty employs approximately 44,752 people worldwide.
Coldwell Banker Realty presently has no subsidiaries across any sectors.
Coldwell Banker Realty’s official LinkedIn profile has approximately 148,870 followers.
Coldwell Banker Realty is classified under the NAICS code None, which corresponds to Others.
No, Coldwell Banker Realty does not have a profile on Crunchbase.
Yes, Coldwell Banker Realty maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/cbrealty.
As of April 02, 2026, Rankiteo reports that Coldwell Banker Realty has experienced 2 cybersecurity incidents.
Coldwell Banker Realty has an estimated 29,970 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach and Ransomware.
Detection and Response: The company detects and responds to cybersecurity incidents through an containment measures with patched the vulnerability, and remediation measures with strengthening security measures, and communication strategy with email notification to affected users, and communication strategy with notified impacted individuals via breach notification..
Title: Substack 2025 Data Breach Exposing User Email Addresses and Phone Numbers
Description: Substack has notified select users that their email addresses and phone numbers were exposed in a security incident last October. An unauthorized third party accessed internal data on February 3, 2025, though passwords, credit card details, and financial information remained secure. The breach involved email addresses, phone numbers, and internal metadata, but there is no evidence the data has been misused.
Date Detected: 2025-02-03
Type: Data Breach
Threat Actor: Unauthorized third party
Title: Anywhere Real Estate Hit by Clop Ransomware Attack, Exposing 17,429 Customers
Description: In August, Anywhere Real Estate disclosed a data breach affecting 17,429 customers, following an attack by the Clop ransomware gang. The cybercriminals infiltrated the company’s Oracle E-Business Suite environment, accessing and potentially exfiltrating sensitive customer data. A breach notification filed with the Maine Attorney General’s Office confirmed the incident, though details on the exact nature of the compromised information remain limited.
Date Publicly Disclosed: 2023-08
Type: Ransomware
Attack Vector: Vulnerability in enterprise software
Vulnerability Exploited: Oracle E-Business Suite
Threat Actor: Clop ransomware gang
Motivation: Extortion
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Email addresses, phone numbers, internal metadata
Brand Reputation Impact: Acknowledged failure to protect user data
Payment Information Risk: None (credit card details and financial information remained secure)

Data Compromised: Sensitive customer data
Systems Affected: Oracle E-Business Suite
Identity Theft Risk: Potential
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Email addresses, phone numbers, internal metadata and Sensitive customer data.

Entity Name: Substack
Entity Type: Company
Industry: Publishing/Technology

Entity Name: Anywhere Real Estate
Entity Type: Corporation
Industry: Real Estate
Customers Affected: 17,429

Containment Measures: Patched the vulnerability
Remediation Measures: Strengthening security measures
Communication Strategy: Email notification to affected users

Communication Strategy: Notified impacted individuals via breach notification

Type of Data Compromised: Email addresses, phone numbers, internal metadata
Sensitivity of Data: Moderate (PII but no financial data)
Personally Identifiable Information: Email addresses, phone numbers

Type of Data Compromised: Sensitive customer data
Number of Records Exposed: 17,429
Sensitivity of Data: High
Data Exfiltration: Potential
Personally Identifiable Information: Potential
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Strengthening security measures.
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by patched the vulnerability.

Regulatory Notifications: Maine Attorney General’s Office

Source: Substack Notification Email

Source: Maine Attorney General’s Office
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Substack Notification Email, and Source: Maine Attorney General’s Office.

Investigation Status: Ongoing
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Email notification to affected users and Notified impacted individuals via breach notification.

Customer Advisories: Email notification sent to affected users

Customer Advisories: Notified impacted individuals
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Email notification sent to affected users and Notified impacted individuals.

Corrective Actions: Strengthening security measures
Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Strengthening security measures.
Last Attacking Group: The attacking group in the last incident were an Unauthorized third party and Clop ransomware gang.
Most Recent Incident Detected: The most recent incident detected was on 2025-02-03.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2023-08.
Most Significant Data Compromised: The most significant data compromised in an incident were Email addresses, phone numbers, internal metadata and Sensitive customer data.
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Patched the vulnerability.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Email addresses, phone numbers, internal metadata and Sensitive customer data.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 17.4K.
Most Recent Source: The most recent source of information about an incident are Maine Attorney General’s Office and Substack Notification Email.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.
Most Recent Customer Advisory: The most recent customer advisory issued were an Email notification sent to affected users and Notified impacted individuals.
.png)
A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 file may lead to information disclosure from the affected product.
V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.
V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Opening a crafted V7 file may lead to information disclosure from the affected product.
V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a crafted V7 file may lead to information disclosure from the affected product.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.