HandyTrac Greystar AZ (US) claims ransomware activity by Threat Actor “ShadowByt3$,” stating they locked out management and staff and are extending negotiations to September 22, 2026 at 3:00pm while possessing key maps/reports, property intelligence and vulnerability logs, employee credential data, financial/vendor records, and administrative portal control. The claim includes “proof of lockout” imagery and asserts the attacker disabled systems and data, with the impacted country listed as #UnitedStates.
Incident Details
- Victim: HandyTrac Greystar AZ WARNING
- Sector: Other
- Country: US
- Actor: ShadowByt3$
- Source: https://mega.nz/figureitout
- Discovered: 2026-09-16T21:53:11.343671+00:00
- Published: 2026-09-16T21:52:54.960881+00:00
Information
- We have locked out the manager and staff, and negotiations are now being extended until September 22, 2026 at 3:00 PM.
- Proof of the lockout is provided through the listed images and onion links.
- Everyone is locked out, and the attackers claim to possess sensitive internal data.
- Exposed data includes physical-to-digital key maps, property intelligence and vulnerability logs, employee identity and credential data, financial and vendor records, and administrative portal control.
- The attackers claim to have disabled and deleted access-related systems and state that website logins are no longer available.
- They reference prior emails sent to executive, privacy, manager, and staff contacts and insist this is a serious corporate incident.

Disclaimer: This post is based on public claims made by the ransomware group "ShadowByt3$". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.