Breach Tracker

Data Breach Tracker: real estate & lending

Real estate and lending companies remain prime targets for ransomware and BEC (business email compromise) attacks.

This tracker highlights recent breaches across mortgage, lending, title/settlement, brokerage, and property management — and the key controls that could have prevented or minimized them. Every entry links to a primary or reputable source.

2026
Breach spring 2026 · disclosed Aug 2026 · Mortgage lender · Nationwide (Texas notice)

Lennar Mortgage — Nationwide (Mortgage Lender)

  • Incident: Two separate, unrelated social-engineering-based cybersecurity events involving unauthorized access to Lennar and Lennar Mortgage systems between May 26 and June 1, 2026; at least 61,000 Texans affected per public disclosure, with the total nationwide count not released.
  • Company stance: Said there was no operational impact and no known misuse of PII such as Social Security numbers; implemented additional security measures and is offering two years of complimentary identity theft monitoring.
  • Aftermath: Two class actions filed in Florida federal court by a former employee and a customer alleging negligence, one seeking deletion of stored PII and stronger cybersecurity controls.
  • Risk-reduction: phishing-resistant MFA, social-engineering / vishing training, and help-desk identity verification procedures.
  • Cost: Not publicly disclosed (litigation ongoing).
  • Source: National Mortgage News →
Breach 2023 · CA fine Aug 2026 · Mortgage lender · Nationwide

Academy Mortgage — Nationwide (Mortgage Lender)

  • Incident: 2023 data breach affecting 284,443 customers, owned by Guild Mortgage.
  • Company stance: Entered a consent order with the California Department of Financial Protection and Innovation (DFPI), which specifically cited the company’s directors for failure to properly oversee operations and conduct audits.
  • Aftermath: Fined by California DFPI; a preliminary class action settlement agreement with plaintiffs is also nearing completion, part of a wider trend of state regulators stepping up enforcement in the mortgage space.
  • Risk-reduction: board-level security oversight, regular independent audits, and documented governance of the security program.
  • Cost: $825,000 California DFPI fine (separate from any class action settlement, which is not yet finalized).
  • Source: National Mortgage News →
Jul 2026 · Bank / mortgage lender · Prattville, AL

River Bank & Trust — Prattville, AL (Bank / Mortgage Lender)

  • Incident: SEC filing disclosed a hacker gained network access June 16, 2026, and deployed ransomware on company servers; breach discovered June 19, 2026. Institution holds ~$3.8B in total assets across 25+ branches in Alabama and Destin, FL.
  • Company stance: Disabled affected administrative accounts and took impacted systems offline immediately; engaged a third-party forensic firm; has not yet determined whether the incident is reasonably likely to materially impact its business or financial condition.
  • Aftermath: Investigation ongoing to determine whether personally identifiable information was accessed or exfiltrated; certain operations impacted while systems are restored.
  • Cost: Not publicly disclosed (investigation ongoing).
  • Source: The Daily Hodl →
Jul 2026 · Vendor breach (accounting firm) · Nationwide wholesale lender

UWM (United Wholesale Mortgage) — Vendor Breach Lawsuit

  • Incident: A customer sued UWM in Michigan federal court, alleging his SSN and other PII were compromised via a 2025 breach at Mercadien, a New Jersey accounting firm; the underlying Mercadien breach affected 400,000+ people nationwide.
  • Company stance: UWM denies experiencing a data breach or having its own systems compromised, disputes any confirmed business relationship with Mercadien in public filings, and calls the lawsuit “without merit.”
  • Aftermath: Filed July 2026; part of a broader pattern of vendor-breach litigation naming lenders even when the underlying breach occurred at a third-party service provider.
  • Risk-reduction: vendor security due diligence, contractual data-handling requirements, and third-party access monitoring.
  • Cost: Not publicly disclosed (litigation ongoing).
  • Source: National Mortgage News →
Jun 2026 · Mortgage lender · Southern California

Optimum First Mortgage — Southern California (Mortgage Lender)

  • Incident: Ransomware group “PEAR” claimed a June 19, 2026 attack and theft of ~9.3 TB of data (mortgage applications, income, employment history, tax records, SSNs, bank details).
  • Company stance: Disputed the volume; internal review found no evidence core loan-origination systems were infiltrated.
  • Aftermath: Proposed consumer class action alleging negligence and lack of encryption; law-firm investigations launched (e.g., Edelson Lechtzin LLP).
  • Cost: Not publicly disclosed (litigation ongoing).
  • Source: Claim Depot → · Morningstar / PR Newswire →
Breach Aug 2023 · disclosed Jan 2024 · settled 2026 · New York

Premium Mortgage Corporation — New York (Residential Mortgage Lender)

  • Incident: Targeted cyberattack between Aug 24–31, 2023, disclosed Jan 10, 2024; ~10,835 customers affected (names, SSNs, payment card and financial account info).
  • Aftermath: Class action settlement received preliminary court approval Jan 23, 2026; final approval hearing held May 14, 2026.
  • Cost: Settlement offers up to $5,000 per claimant for documented extraordinary losses, $25/hour for up to 4 hours of lost time, or a flat $50 alternative payment; total fund value not disclosed.
  • Source: ClassAction.org →
Breach May 2025 · disclosed Mar 2026 · Melville, NY (49 states)

US Mortgage Corporation — Melville, NY (Mortgage Lender, 49 states)

  • Incident: Unauthorized network access May 13–14, 2025; exposed names, DOB, contact info, SSNs, financial / mortgage account info, and limited medical / insurance info.
  • Company stance: Not publicly disputed; engaged third-party cybersecurity experts upon detection.
  • Aftermath: Notice mailed March 5, 2026 — over 260 days after detection; class action filed March 23, 2026 (E.D.N.Y.) alleging unencrypted SSNs.
  • Cost: Not publicly disclosed (litigation ongoing).
  • Source: MPA →
Breach Nov 2025 · disclosed Feb 2026 · Real estate brokerage franchisor · Nationwide

Anywhere Real Estate — Nationwide (Brokerage Franchisor: Coldwell Banker, Century 21, Sotheby’s International Realty, Cartus)

  • Incident: CL0P ransomware group exploited a global Oracle E-Business Suite vulnerability, gaining access to Anywhere’s Oracle EBS environment in late Nov 2025 and downloading historical employee/franchisee data; 17,429 individuals affected (names, addresses, DOB, SSNs, job details) across Anywhere, Cartus, National Realty Trust, Title Resources Group, and Real Estate Franchise Group.
  • Company stance: Said impact was limited to historical employee data, with no consumer transaction data involved and no impact to business operations; worked with Oracle and third-party experts to contain and remediate.
  • Aftermath: Disclosed to attorneys general in Maine, New Hampshire, Texas, and Vermont, and the Massachusetts Office of Consumer Affairs, in early Feb 2026; offering two years of Experian IdentityWorks credit monitoring and identity protection.
  • Risk-reduction: third-party / vendor patch management, timely patching of enterprise software (Oracle EBS), and data minimization for historical employee records.
  • Cost: Not publicly disclosed.
  • Source: HousingWire →
Feb 2026 · Wholesale / correspondent lender · Costa Mesa, CA

Plaza Home Mortgage — Costa Mesa, CA (Wholesale / Correspondent Lender)

  • Incident: Ransomware group “SilentRansomGroup” claimed a Feb 27, 2026 breach; initial reports cited ~54 users / 10 employees affected, later estimates put scope near 138,000.
  • Company stance: Disputed the higher figure; said security controls detected the access and it shut down the attack immediately.
  • Aftermath: Formal victim notification delayed until May 29, 2026 (via Simpluris); now facing class action lawsuits.
  • Cost: Not publicly disclosed (litigation ongoing).
  • Source: HousingWire →
Fall 2025 · Vendor breach · Industry vendor

SitusAMC — (Industry Vendor, not a direct lender)

  • Incident: Cyberattack last fall; scope of impact on consumers, partner banks, and lenders undisclosed.
  • Aftermath: Class action settlement agreed for affected individuals.
  • Cost: $5.3 million class action settlement for 662,792 class members.
  • Source: National Mortgage News →
Breach 2021 · multistate settlement

Bayview Asset Management (+ 3 affiliates)

  • Incident: 2021 data breach; handling later scrutinized by multiple states.
  • Aftermath: Settled multistate allegations that its breach response failed to meet certain standards.
  • Cost: $26 million class action settlement covering over 5.7 million affected consumers.
  • Source: National Mortgage News →
2026 · Unconfirmed claim · Nationwide

Finance of America — Nationwide (Mortgage Lender / Servicer)

  • Incident: A ransomware gang claimed a hack; the company has not disclosed any incident itself.
  • Company stance: No disclosure made.
  • Aftermath: A consumer filed an early class action based solely on the gang’s claim.
  • Cost: Not publicly disclosed.
  • Source: National Mortgage News →
Ransomware · post-merger · Mortgage lender

Pacific Residential Mortgage — (Mortgage Lender)

  • Incident: Ransomware attack discovered just weeks after completing a merger with an Ohio-based lender.
  • Cost: Not publicly disclosed.
  • Source: National Mortgage News →
2025
Sep–Oct 2025 · Property management · Nationwide (Massachusetts notice)

Glenwood Management Corp. — Nationwide (Property Management)

  • Incident: Unauthorized access to systems discovered September 2025; attackers may have accessed files containing personal information for 8,146 individuals.
  • Company stance: Investigators assessed the attacker’s primary goal as financial extortion rather than data theft.
  • Aftermath: Reported to the Massachusetts Attorney General’s office in Oct 2025.
  • Risk-reduction: ransomware / extortion readiness, network segmentation, offline backups.
  • Cost: Not publicly disclosed.
  • Source: Massachusetts AG filing →
Aug 2025 · Mortgage lender · New Jersey (22 states)

NJ Lenders Corp. — New Jersey (22 states)

  • Incident: Unauthorized network access Aug 18, 2025; confirmed exposure Sept 12, 2025 — names, SSNs, driver’s license numbers, DOB, financial account info.
  • Aftermath: Regulatory filings with Maine, Massachusetts, and Vermont AGs. Class action settlement received preliminary court approval July 2026; class members can claim up to $2,500 for documented out-of-pocket losses between Aug. 18, 2025 and Oct. 1, 2026.
  • Risk-reduction: MFA, network segmentation, continuous monitoring, encryption of retained records.
  • Cost: $100,000 total class action settlement for a class of approximately 30,000 members.
  • Source: Claim Depot (state AG filings) → · National Mortgage News →
Jul 2025 · Non-bank lender · Irvine, CA

American Lending Center — Irvine, CA (Non-bank Lender)

  • Incident: Ransomware attack exposing PII for ~123,158 people (names, DOB, SSNs).
  • Aftermath: Detected July 2025; investigation completed April 2026, delaying notifications.
  • Risk-reduction: MFA, network segmentation, offline backups, faster detection / notification.
  • Cost: Not publicly disclosed.
  • Source: California Attorney General →
Jul 2025 · Third-party vendor · Mortgage lender

New American Funding — (Mortgage Lender)

  • Incident: July 2025 breach involving a third-party vendor, potentially compromising customer data.
  • Aftermath: Reported to the California Attorney General.
  • Cost: Not publicly disclosed.
  • Source: HousingWire →
Jun 2025 · Mortgage lender · Virginia

McLean Mortgage Corporation — Virginia (Mortgage Lender)

  • Incident: Breach exposed personal and financial info for ~30,453 individuals (SSNs, account numbers).
  • Aftermath: Regulatory filings with Maine, Massachusetts, New Hampshire, and Vermont AGs.
  • Risk-reduction: MFA, encryption of loan files, phishing-resistant controls, prompt detection.
  • Cost: Not publicly disclosed.
  • Source: Claim Depot (state AG filings) →
Mar 2025 · Mortgage lender · California

Intelliloan, Inc. — California (Mortgage Lender)

  • Incident: RansomHub claimed an attack exposing names, addresses, SSNs, driver’s license / ID numbers, financial account numbers, and DOB.
  • Aftermath: Regulatory filings with California, Texas, and Massachusetts AGs.
  • Risk-reduction: offline backups, EDR, least-privilege access, rapid containment.
  • Cost: Not publicly disclosed.
  • Source: Cybernews →
Feb 2025 · Property management · Nationwide (Vermont notice)

Keystone Pacific Property Management — Nationwide (Property Management)

  • Incident: Unusual system activity detected Feb 2025; investigation confirmed an unauthorized actor accessed personal information (names and other identifying details) between Feb 7–10, 2025.
  • Aftermath: Disclosed to the Vermont Attorney General’s office June 2025.
  • Risk-reduction: continuous monitoring, least-privilege access, faster detection.
  • Cost: Not publicly disclosed.
  • Source: Vermont AG filing →
2024
Breach Sep–Oct 2024 · disclosed Apr 2025 · Property management · Multi-state

CRM Residential (formerly Community Realty Management) — Multi-state (Property Management)

  • Incident: Unauthorized access to several company email accounts between Sept 10–Oct 22, 2024, discovered April 2025; 11,787 individuals affected. Compromised data included DOB, SSNs, driver’s license and passport numbers, financial and payment card data, and medical data.
  • Aftermath: Notice provided via PR Newswire and state filings following investigation.
  • Risk-reduction: MFA on email, phishing-resistant controls, faster breach detection.
  • Cost: Not publicly disclosed.
  • Source: PR Newswire →
Jan 2024 · Mortgage lender · Nationwide

LoanDepot — Nationwide (Mortgage Lender)

  • Incident: ALPHV/BlackCat ransomware attack; ~16.9M customers affected (names, DOB, SSNs); major operational disruption.
  • Risk-reduction: EDR, network hardening, offline backups, IR-plan readiness.
  • Cost: ~$27 million in reported incident-related expenses.
  • Insurance: Partial coverage only. By mid-2024, LoanDepot had incurred more than $41M in attack-related expenses but had received just $15M in insurance reimbursements at that point, with no confirmed timeline for further payment — roughly a third of costs covered to date.
  • Source: SecurityWeek → · Cybersecurity Dive →
2023
Nov 2023 · Title & escrow · Nationwide

Fidelity National Financial — Nationwide (Title & Escrow)

  • Incident: Suspected ALPHV/BlackCat ransomware attack.
  • Aftermath: Multi-day operational disruption; closings delayed.
  • Risk-reduction: hardened escrow systems, vendor security reviews, tested continuity plans.
  • Cost: Not publicly disclosed (operational / reputational losses from closing delays not quantified).
  • Source: Cybersecurity Dive →
Oct–Nov 2023 · Mortgage servicer · Nationwide

Mr. Cooper (Nationstar Mortgage) — Nationwide (Mortgage Servicer)

  • Incident: Intrusion Oct 30–Nov 1, 2023; forced payment systems offline; ~14.7M customers affected (names, addresses, SSNs, DOB, bank account numbers).
  • Aftermath: A Texas federal court later ruled affected borrowers had standing to sue.
  • Risk-reduction: continuous monitoring, encryption, least-privilege access, formal cybersecurity program.
  • Cost: ~$25 million estimated response cost.
  • Insurance: Mr. Cooper sued its own insurers (National Union Fire Insurance and Berkshire Hathaway Specialty) in Nov 2024, alleging improper denial of coverage on ~$30M in losses. National Union agreed to cover only $300,000 — a denial of nearly 99% of the claimed loss — while Berkshire took no coverage position at all, delaying payment.
  • Source: BleepingComputer → · National Mortgage News →
2021
Dec 2021 · Bank / mortgage lender · Nationwide

Flagstar Bank — Nationwide (Bank / Mortgage Lender)

  • Incident: Attackers accessed the corporate network — second major breach in a year; ~1.55M customers affected (names, SSNs).
  • Risk-reduction: retiring vulnerable file-transfer tools, network segmentation, faster detection, identity protection.
  • Cost: $31.5 million settlement covering both 2021 breaches.
  • Source: Cybersecurity Dive →
Breach Nov 2019–Sep 2021 · settled Aug 2025 · Property management · Massachusetts

Peabody Properties, Inc. — Massachusetts (Property Management)

  • Incident: Five separate phishing-driven breaches between Nov 2019 and Sept 2021, exposing SSNs, driver’s license numbers, and bank account details for nearly 14,000 individuals.
  • Aftermath: Company delayed notifying affected consumers for months after the first breach; Massachusetts AG investigation followed.
  • Risk-reduction: phishing training, MFA on email, prompt breach notification procedures.
  • Cost: $795,000 settlement with the Massachusetts Attorney General (Aug 2025) for inadequate data security and notification-law violations.
  • Source: Massachusetts AG →
2019
May 2019 · Title & settlement · Nationwide

First American Financial — Nationwide (Title & Settlement)

  • Incident: EaglePro application flaw (IDOR) exposed ~885M document images (SSNs, financial data, driver’s licenses, 2003–2019).
  • Risk-reduction: secure SDLC, access controls, vulnerability management.
  • Cost: SEC penalty $487,616; NYDFS penalty $1 million (total regulatory fines ~$1.49M; broader remediation costs not disclosed).
  • Source: U.S. SEC →
Mar 2019 · Mortgage banker · Multi-state

Residential Mortgage Services — Multi-state (Mortgage Banker)

  • Incident: Phishing compromised an employee email account containing applicant data.
  • Risk-reduction: MFA on email, phishing training, prompt investigation, regulatory compliance.
  • Cost: NYDFS fine of $1.5 million.
  • Source: NY Dept. of Financial Services →
Summaries are based on public reports from the linked sources and reflect information available at the time of writing. This page is provided for general educational purposes and is not legal advice or a statement about any company's current security posture.
Insurance coverage outcomes are disclosed publicly only when litigation or SEC filings reveal them. Most companies do not release this information, so an “Insurance” line is only shown above where public records confirm coverage, denial, or a shortfall.
Last updated: August 2026. This page is updated periodically.
Cost of a breach

The cost of cleaning up — and why insurance may not help

What incident response actually costs

Small businesses typically pay $120,000 to $1.24M to respond to and resolve a security incident. That figure covers forensic investigation, legal counsel, breach notification and credit monitoring, and emergency IT remediation — often before operations even fully stabilize. Bare-minimum system recovery alone can run $15,000–$50,000.

Compare that to prevention: a comprehensive cybersecurity program for a 50-person company typically runs $75,000–$150,000/year — a small fraction of even the low end of that breach-cost range. A tested incident response plan is one of the biggest cost reducers in IBM’s Cost of a Data Breach research, cutting average breach costs by well over $1M in recent years.

Why cyber insurance often doesn’t pay out

Most denials aren’t fraud — they’re gaps between what a business claimed on its application and what was actually running when the attack hit. 82% of denied cyber insurance claims involved organizations without fully implemented MFA, and 41% of applications are denied on first submission, most often over missing MFA or inadequate endpoint protection.

In Travelers v. International Control Services (2022), Travelers discovered after a ransomware attack that MFA wasn’t as fully deployed as the company had attested on its application. Rather than litigate, the parties agreed to a stipulated judgment voiding the policy from inception — leaving the ransomware claim unpaid.

The City of Hamilton, Ontario faced a similar outcome on a much larger scale: after a February 2024 ransomware attack that cost the city roughly $18.4M to recover from, its insurer denied a $5M claim because MFA hadn’t been consistently enforced across every department — despite being partially rolled out.

Source: CBC News →

A security program isn’t just about stopping an attack — it’s what makes your insurance policy actually pay out if one gets through.

Don't want to be the next headline?

Most of these incidents trace back to a handful of controls that were missing. Protect your firm from these risks — get a free M365 security assessment and see where your firm stands.

Book a Free 20-Minute Assessment