AppFolio, Inc. sent breach notification letters referencing incidents dated 08/08/2025 and 08/18/2025, and the company reported the matter to the California Attorney General on 10/06/2025. The copy of the letter we reviewed focuses heavily on the protective steps recipients can take rather than a detailed description of how the incident occurred, so the exact method used — whether hacking, an internal error, or something else — isn’t stated in the material available to us.
The letter doesn’t spell out the full scope of who was affected, but it does confirm that at least 188 people in Rhode Island received notice, and language addressed to residents of Connecticut, the District of Columbia, Maryland, New York, North Carolina, and West Virginia suggests the mailing went out broadly across the country. Because AppFolio provides property management software used by landlords and tenants, anyone whose information passes through that platform could plausibly be included, but we don’t have a total count to share.
What personal information does this letter actually say was involved?
- The excerpt of the notice we have access to does not list the specific categories of personal data exposed in this incident.
- The letter does walk recipients through placing credit freezes and fraud alerts, steps that are typically recommended when identifying information like a Social Security number or similar could be at risk, but this document does not explicitly confirm that.
- If you received a physical copy of this letter, check the section above the boilerplate legal language included here — companies typically state the exact data types near the top of the notice.
No mention of free credit monitoring or identity protection services being offered by AppFolio appears in the text we reviewed. If your letter includes an enrollment code or web portal that isn’t reflected here, follow those instructions directly, since they would come from the company itself.
Steps to take if you received this notice
- Place a free security freeze with Equifax, Experian, and TransUnion individually — this stops most new-account fraud since lenders generally won’t extend credit without seeing your file.
- Consider an initial or extended fraud alert instead if you’d rather keep your credit accessible while still adding a layer of protection.
- Pull your free credit reports and look for accounts or inquiries you don’t recognize.
- Because the specific data exposed isn’t confirmed here, it’s worth signing up for a service like Aura or LifeLock so you’ll get an alert if your personal information turns up somewhere it shouldn’t.
- If you’re active-duty military, ask about an Active Duty Military Fraud Alert, which lasts a year and can be renewed for your full deployment.
- Keep the letter itself, along with any reference or claim numbers, in case you need to prove notification timing later.
If you have questions about this notice, AppFolio can be reached at (866) 648-1536 or by mail at 70 Castilian Dr., Goleta, CA 93117.