TL;DR
- Yes Communities LLC, a Denver-based residential property management company serving thousands of residents nationwide, suffered a data breach between December 9-11, 2024.
- The breach exposed highly sensitive personal information including names, addresses, Social Security numbers, and driver’s license numbers of over 2,490 residents.
- Yes Communities waited more than two months to notify victims, finally sending breach notices on February 24, 2025.
- The lawsuit alleges the company failed to implement basic cybersecurity measures including encryption, multi-factor authentication, and intrusion detection systems despite FTC guidelines and industry standards.
- Residents now face a lifetime risk of identity theft, yet Yes Communities offered only 12 months of credit monitoring.
- The complaint charges negligence, negligence per se under the Federal Trade Commission Act, breach of contract, and unjust enrichment.
The 48-page federal complaint reveals that Yes Communities collected residents’ most sensitive data as a condition of housing, then stored it without encryption while cybercriminals accessed their systems for three consecutive days.
When Your Landlord Loses Your Social Security Number
In December 2024, while residents of Yes Communities properties across America were preparing for the holidays, cybercriminals were spending three days inside the company’s computer systems, copying the most sensitive personal information a person can possess. Names. Home addresses. Social Security numbers. Driver’s license numbers. Everything needed to steal an identity and ruin a life.
Yes Communities knew about the breach. The company’s own notice admits it “detected unusual activity on some of its computer systems.” But it would be 76 days before Michelle O’Leary and thousands of other residents received a single word of warning.
By the time the breach notification letters arrived on February 24, 2025, the stolen data had already been sitting on criminal servers for more than two months. In the dark web marketplace, that information was likely already for sale, already being compiled into “Fullz packages,” complete identity dossiers that criminals trade and exploit for years.
This is the new housing economy. You hand over the keys to your entire identity just to have a roof over your head. And when the corporation holding that data fails to protect it, you’re the one who pays the price for the rest of your life.
The Company: Private Equity Meets Residential Real Estate
Yes Communities LLC operates out of Denver, Colorado, at 5050 South Syracuse Street. Founded in 2008, the company manages residential communities across the United States, employing over 1,161 people and generating approximately $202 million in annual revenue. The company’s business model centers on providing homes for rent or purchase, primarily in manufactured housing and mobile home communities.
To become a resident, you must provide Yes Communities with extensive personal information. It is not optional. The company requires Social Security numbers, driver’s license numbers, addresses, and other identifying data as a condition of tenancy. According to the complaint, “as a condition of receiving residential services, Yes Communities requires its residents entrust it with highly sensitive personal information.”
In exchange for this treasure trove of personal data, Yes Communities made promises. The company’s privacy policy, accessible on its website, explicitly states: “YES! Communities secures Your Personal Information from unauthorized access, use or disclosure. YES! Communities secures the Personal Information You provide on computer servers in a controlled, secure environment, protected from unauthorized access, use or disclosure.”
The policy goes further: “YES! Communities will protect the privacy and security of Personal Information according to YES! Communities’ Privacy Policy, regardless of where it is processed or stored.”
Those promises, according to the federal lawsuit filed by Michelle O’Leary, were broken.
The Breach: Three Days of Unauthorized Access
The data breach occurred between December 9, 2024, and December 11, 2024. According to Yes Communities’ own breach notification, the company “detected unusual activity on some of its computer systems.” An investigation revealed that “an unauthorized party had access to certain company files” during that three-day window.
Three days. That is an eternity in a cyberattack. Professional intrusion detection systems are designed to identify and contain unauthorized access within minutes or hours. The fact that cybercriminals had free rein over Yes Communities’ systems for 72 consecutive hours suggests either a catastrophic failure of monitoring systems or an absence of such systems entirely.
The complaint alleges that Yes Communities failed to implement industry-standard security measures that could have prevented the breach or at least detected it faster: no proper encryption of sensitive data, no multi-factor authentication requirements, no intrusion detection systems actively monitoring for suspicious activity, no network segmentation to isolate sensitive databases.
These are not exotic cybersecurity measures. They are baseline protections recommended by the Federal Trade Commission, the National Institute of Standards and Technology, and the Center for Internet Security. They are the digital equivalent of locking your doors.
But according to the lawsuit, Yes Communities left the doors wide open.
The Delay: 76 Days of Silence
Yes Communities discovered the breach at some point after December 11, 2024. The exact date of discovery is not disclosed in the company’s breach notification. But the timeline is damning: breach occurs December 9-11, 2024; Texas Attorney General notification filed February 25, 2025; breach notification letters sent to victims February 24, 2025.
That means residents went more than two months without knowing their most sensitive personal information had been stolen. Two months during which cybercriminals could compile, sell, and exploit that data. Two months during which victims could have been placing fraud alerts, freezing credit reports, and monitoring accounts for suspicious activity.
The lawsuit makes the delay’s consequences explicit: “It must also be noted that there may be a substantial time lag between when harm occurs and when it is discovered, and also between when PII and/or personal financial information is stolen and when it is used.”
The U.S. Government Accountability Office has documented this reality in its studies of data breaches: “Law enforcement officials told us that in some cases, stolen data may be held for up to a year or more before being used to commit identity theft. Further, once stolen data have been sold or posted on the Web, fraudulent use of that information may continue for years.”
Every day Yes Communities remained silent was another day the stolen information circulated deeper into criminal networks.
The Non-Financial Ledger
Michelle O’Leary is a resident of Ohio. She entrusted Yes Communities with her personal information because she had no choice. You cannot rent a home without providing that data. The implicit bargain is simple: I give you my Social Security number, you protect it.
Now she lives with permanent anxiety. Every unexpected phone call might be a scammer who bought her information on the dark web. Every credit card application she didn’t file might be fraud. Every tax season brings the fear that someone has already filed a return in her name. She must monitor her credit reports, her bank accounts, her medical records for the rest of her life.
This is not theoretical harm. The Identity Theft Resource Center’s 2023 Consumer Impact Report, based on interviews with over 14,000 identity crime victims, documents the catastrophic consequences: 77 percent experienced financial problems, 29 percent experienced losses exceeding $10,000, 40 percent were unable to pay bills, 28 percent were denied credit or loans, 37 percent became indebted, 87 percent experienced feelings of anxiety, 67 percent had difficulty sleeping, 51 percent suffered panic or anxiety attacks.
Yes Communities’ response? Twelve months of credit monitoring. Twelve months to address a threat that will last the rest of O’Leary’s life.
The lawsuit notes with bitter clarity: “One year of credit monitoring is not sufficient given that Plaintiff O’Leary will now experience a lifetime of increased risk of identity theft and other forms of targeted fraudulent misuse of her Private Information.”
O’Leary has already spent hours she will never get back: researching the breach, reviewing financial accounts for fraud, researching credit monitoring options, contacting credit bureaus. Time that could have been spent with family, at work, living her life. Time stolen by corporate negligence.
And she is one of at least 2,490. Each of them now carries the same burden. Each of them must now spend years looking over their shoulders, wondering when the theft of their data will become the theft of their financial lives.
Legal Receipts
The complaint filed in the United States District Court for the District of Colorado lays out the case with procedural precision. Here is what Yes Communities’ own breach notification admitted:
“Based on the Notice, Yes Communities detected unusual activity on some of its computer systems. In response, the company conducted an investigation which revealed that an unauthorized party had access to certain company files between December 9, 2024 and December 11, 2024.”
That is the company’s own description. “Unusual activity.” “Unauthorized party.” “Access to certain company files.” Clinical language that obscures the human cost: thousands of people’s Social Security numbers in the hands of criminals.
The complaint charges that Yes Communities violated duties established under the Federal Trade Commission Act:
“Section 5 of the FTC Act, 15 U.S.C. ยง 45, prohibits ‘unfair . . . practices in or affecting commerce,’ including, as interpreted and enforced by the FTC, the unfair act or practice by businesses like Yes Communities of failing to use reasonable measures to protect Private Information they collect and maintain from consumers.”
The lawsuit points to specific security failures:
“Yes Communities breached its duties, and thus was negligent, by failing to use reasonable measures to protect Class Members’ Private Information. The specific negligent acts and omissions committed by Defendant include, but are not limited to, the following: a. Failing to adopt, implement, and maintain adequate security measures to safeguard Class Members’ Private Information; b. Failing to adequately monitor the security of its networks and systems; c. Failing to periodically ensure that its email system maintained reasonable data security safeguards; d. Allowing unauthorized access to Class Members’ Private Information; e. Failing to comply with the FTCA.”
There are no ambiguities here. The charges are specific, the failures documented, the consequences clear.
Societal Impact Mapping
Economic Inequality
Yes Communities serves a specific market: residents who need affordable housing, often in manufactured housing communities. These are not luxury renters with extensive financial cushions. When identity theft strikes this population, the consequences are devastating.
A fraudulent credit card in the name of someone living paycheck to paycheck can destroy their ability to access emergency funds. A stolen identity used to file a fake tax return can delay a refund that a family desperately needs. Debt collection calls for loans they never took out can make it impossible to rent the next apartment when they need to move.
The lawsuit notes that victims may face “difficulty obtaining loans, opening bank accounts, or securing housing” as a result of identity theft. For residents of affordable housing communities, these barriers can mean the difference between stability and homelessness.
Yes Communities collected over $202 million in annual revenue. The company could afford industry-standard cybersecurity. It chose not to implement it. Now its residents, many of whom are economically vulnerable, will pay the price for decades.
Public Health
The Identity Theft Resource Center’s research makes the public health impact of data breaches undeniable. Victims experience anxiety, depression, insomnia, and panic attacks at rates that mirror those seen in trauma survivors. The lawsuit cites these statistics directly: 87 percent experienced anxiety, 67 percent had difficulty sleeping, 51 percent suffered panic or anxiety attacks.
This is not a financial problem. It is a public health crisis inflicted by corporate negligence. The stress of monitoring accounts, disputing fraudulent charges, and living with the constant fear of the next identity theft incident takes a measurable toll on mental and physical health.
Environmental Degradation
While this particular breach does not directly implicate environmental harm, the connection between corporate accountability failures is instructive. A company that will not invest in basic cybersecurity to protect its residents is operating from the same cost-cutting playbook that leads to environmental corners being cut. The mentality is identical: externalize the risk onto the people who can least afford it, keep the profits internal.
The Dark Web Marketplace
Where did the stolen data go? The lawsuit provides a window into the criminal economy that now holds Michelle O’Leary’s information and that of thousands of others.
According to the PrivacyAffairs Dark Web Price Index, a batch of 10 million USA email addresses sells for $120. More complete “Fullz packages,” which contain enough information to fully impersonate someone, sold for $30 in 2017 and have only increased in value as breaches become more common and criminals more sophisticated.
Experian reports that stolen credit card numbers sell for $5 to $110 on the dark web. But Social Security numbers are worth far more because they are permanent identifiers that cannot be changed. You can cancel a credit card. You cannot cancel your Social Security number.
The complaint explains how criminals use even partial information to build complete identity profiles through a technique called “social engineering”: “Armed with just a name and date of birth, a data thief can utilize a hacking technique referred to as ‘social engineering’ to obtain even more information about a victim’s identity, such as a person’s login credentials or Social Security number.”
This is the “mosaic effect.” Each piece of leaked data from each breach can be combined with other leaks to create a frighteningly complete picture of a person’s identity. Yes Communities’ breach does not exist in isolation. The stolen data from this incident will be cross-referenced with data from other breaches to create those Fullz packages that criminals trade and exploit.
The lawsuit is blunt about the implications: “Once stolen data have been sold or posted on the Web, fraudulent use of that information may continue for years. As a result, studies that attempt to measure the harm resulting from data breaches cannot necessarily rule out all future harm.”
Michelle O’Leary and the thousands of other victims will be dealing with the consequences of this breach for the rest of their lives, while the criminals who stole their data continue to profit.
What Now?
The lawsuit is pending in the United States District Court for the District of Colorado under Case No. 1:25-cv-692. It seeks class action certification for all individuals nationwide whose private information was compromised in the breach.
The plaintiff is represented by Josh Sanford of Sanford Law Firm, PLLC, and Jarrett Ellzey and Leigh S. Montgomery of EKSM, LLP. Yes Communities can be served via its registered agent, Cogency Global, Inc., at 850 New Burton Road, Suite 201, Dover, DE 19904.
The complaint demands a jury trial and seeks the following relief: certification as a class action under Federal Rule of Civil Procedure 23, monetary damages including actual damages and statutory damages, injunctive relief requiring Yes Communities to implement adequate cybersecurity measures, lifetime credit monitoring and identity theft insurance for all affected residents, costs and attorney fees.
Regulatory Oversight
Several government bodies have jurisdiction over corporate data security failures:
- The Federal Trade Commission enforces Section 5 of the FTC Act, which prohibits unfair and deceptive practices including inadequate data security.
- State Attorneys General can bring enforcement actions under state consumer protection laws. The Texas Attorney General has been notified of this breach.
- The Consumer Financial Protection Bureau has authority over companies that handle consumer financial data.
Direct Action for Affected Residents
If you are or were a Yes Communities resident, consider these steps:
- Place a fraud alert with all three major credit bureaus: Equifax, Experian, and TransUnion. This is free and lasts one year, and can be extended to seven years if you file an identity theft report.
- Consider placing a credit freeze, which prevents anyone from opening new credit accounts in your name. Freezes are free and can be lifted temporarily when you need to apply for credit.
- Request your free annual credit reports from AnnualCreditReport.com and review them carefully for accounts you did not open.
- Monitor your bank and credit card statements for unauthorized transactions.
- File your tax return early each year to prevent criminals from filing fraudulent returns in your name.
- Consider enrolling in credit monitoring services beyond the 12 months Yes Communities offered, since your risk extends for your lifetime.
- Document all time and expenses you incur as a result of this breach, as these may be recoverable damages.
Grassroots Resistance
This breach is a symptom of a larger problem: the corporatization of housing has created information asymmetries and power imbalances that leave renters vulnerable. When your landlord is a private equity-backed corporation managing thousands of units, you are not a tenant. You are a data point. And when that data is not protected, you have no recourse except expensive, time-consuming litigation.
Organize with other tenants. Demand transparency about data security practices before signing leases. Support local and state legislation that imposes real penalties for data security failures, penalties harsh enough to make corporations invest in protection rather than risk the fine.
The problem is not just Yes Communities. The problem is a housing market where corporate landlords collect vast troves of sensitive personal data with no enforceable obligation to protect it and no meaningful consequences when they fail.



