Last Update: 08/01/2026 at 1:00 PM EST

Mortgage Lenders Report Sensitive Data Breaches

Coverage from Morningstar, The Irish Times, and others

Articles

28

Active Days

97

The Topic

Mortgage Lenders Report Sensitive Data Breaches topic image

Mortgage lenders and related financial organizations are reporting unauthorized access, ransomware activity, and possible theft of sensitive customer or employee information. Exposed data may include Social Security numbers, tax and income records, financial account details, identification data, and account credentials, increasing potential identity-theft and fraud risks. The incidents also show how supplier compromises and delayed notification can extend the impact beyond the initially targeted systems.

First Article: 04/18/26

Latest Article: 07/23/26

Summary

  • Plaza Home Mortgage, Optimum First Mortgage, First National Holdings, and Impac Mortgage Holdings reported incidents involving possible access to sensitive personal or financial information.
  • Optimum First Mortgage was targeted by the Pear ransomware group, which claimed the attack and threatened to leak data unless payment was made.
  • Potentially exposed records include Social Security numbers, tax information, income and employment history, bank account details, driver’s license data, health insurance information, and employee credentials.
  • A Pitney Bowes supplier breach put contact details for 137 Revenue Commissioners employees in Ireland at risk, but Revenue said taxpayer data and passwords were not involved.
  • Organizations are offering credit monitoring, fraud alerts, and other protective measures while law firms investigate possible claims on behalf of affected individuals.
  • The incidents span both newly detected activity and older intrusions disclosed or notified in 2026, complicating assessment of when exposure occurred and how many people were affected.

History

07/23/2026

The story now adds a broader set of exposed data types and sharpens the framing around delayed disclosures, making the breach timeline and potential impact more concerning. It also shifts from a simple list of incidents to a clearer picture of supplier risk, ransomware extortion, and older intrusions surfacing later.

07/22/2026

The story has shifted from a general pattern of financial-sector breach disclosures to a more specific wave of mortgage-lender incidents, including ransomware, unauthorized access, and supplier compromise. The added reports also sharpen the operational response picture, with notifications, credit-monitoring offers, and legal investigations now central.

Full History

Featured

Timeline: 97 Days

Apr 18May 9May 23Jun 13Jun 27Jul 18

Additional Articles

⭐⭐⭐⭐⭐

The Irish Times05-19-2026
Revenue Commissioners Ireland notified employees in late April about possible personal-data exposure following a Pitney Bowes ransomware attack affecting a supplier relationship.
National Mortgage News / Andrew Martinez07-23-2026
McLean Mortgage agreed to a Virginia federal court per-claim settlement after a late-2024 cyberattack potentially exposed SSNs for 30,453 customers and employees.
ManageEngine05-11-2026
In November 2025, a mortgage services vendor breach exposed customer PII and financial data after attackers targeted the mortgage supply chain, prompting FBI notification and rapid reporting concerns.
Rescana06-09-2026
SoFi Hong Kong disclosed June 8, 2026, that unauthorized third-party vendor access exposed customer PII identified by data fields including names and dates of birth.
msdlegal07-08-2026
Markel Insurance investigated a potential class action after mailed notices beginning July 7, 2026 reported unauthorized access to personal and protected health information.

⭐⭐⭐

Top Class Actions06-18-2026
San Diego mortgage lender Plaza Home Mortgage disclosed May 29 that a Feb. 17 employee computer intrusion may have exposed employee personal data.
Claim Depot04-18-2026
Impac Mortgage Holdings disclosed a 2024 unauthorized access incident affecting names and Social Security numbers, with regulator and consumer notifications issued in 2026.
Claim Depot06-03-2026
Plaza Home Mortgage notified consumers in May 2026 after unauthorized access beginning Feb 17, 2026, may have exposed sensitive personal data.
Claim Depot06-08-2026
Fintech Holdco LLC disclosed on June 5, 2026 a Massachusetts data breach potentially affecting 58 residents, including Social Security numbers.
Mortgage Professional / Tez Romero04-28-2026
Monica P. Espejo filed an April 27, 2026 class action against Impac Mortgage Holdings in California over delayed notice of a Social Security number data breach.
Lincoln Journal06-20-2026
Edelson Lechtzin LLP is investigating a potential class action over an AssetMark, Inc. data breach, citing exposure of Social Security numbers, financial data, and government IDs.
National Mortgage News / Andrew Martinez07-02-2026
Ricky LaFountain sued United Wholesale Mortgage in federal court in Michigan in connection with a Mercadien vendor breach disclosed in November.
HousingWire06-01-2026
Plaza Home Mortgage disclosed May 29 notifications after unauthorized access beginning around Feb. 17, 2026 potentially exposed customer and employee identifiers.
The Astorian07-18-2026
Wolf Haldenstein Adler Freeman & Herz LLP is investigating a First National Holdings data breach disclosed in July 2026, with potential exposure including Social Security, finances, and health insurance.
The Malone Telegram07-13-2026
Edelson Lechtzin LLP investigates a First National Holdings data breach reported to the Vermont Attorney General around July 9, 2026, citing potential exposure of Social Security and financial data.
Pluang06-01-2026
Industrial Acceptance Corporation disclosed a February 2025 breach exposing 79,216 people2 Social Security and driver's license data, with Murphy Law Firm considering class action.
Westlaw Today / Westlaw Today06-29-2026
Heather Morrison filed a proposed class action in the Central District of California alleging Optimum First Inc. security failures enabled PEAR ransomware to exfiltrate unencrypted customer PII.
McShane & Brady06-09-2026
McShane & Brady, LLC investigates a Plaza Home Mortgage data breach affecting 137,000+ people after unauthorized employee-computer access in February 2026.
Cision PR Newswire04-21-2026
Edelson Lechtzin LLP investigates a potential class action after Impac Mortgage Holdings, Inc. identified unauthorized access involving Social Security numbers in March 2024.
Cision PR Newswire05-20-2026
Beacon Mutual Insurance Company disclosed a January 2026 data breach affecting Social Security numbers, and Edelson Lechtzin LLP is investigating potential class action claims.
Cision PR Newswire06-12-2026
On February 17, 2026, Plaza Home Mortgage identified suspicious network activity tied to unauthorized employee-computer access, potentially exposing sensitive data affecting up to 137,976 people.
ClassAction.org06-08-2026
Attorneys sought a class action after a Fintech Holdco breach potentially exposed Social Security numbers, with Massachusetts reporting dated June 5, 2026 and Tampa-based breach notices mailed to affected people.
ClassAction.org06-09-2026
MasTec, after a 2025 third-party zero-day breach, disclosed exposure of SSNs and financial details affecting 25,220 people and faces potential class action.
Sauder Schelkopf / Joseph Sauder04-18-2026
Sauder Schelkopf LLP is evaluating legal claims after Impac Mortgage Holdings notified consumers in March 2026 about unauthorized access from February 21 to March 20, 2024.
Federman & Sherwood / Caroline Chesher07-21-2026
Federman & Sherwood investigates a Pinnacle Financial Partners, Inc. data breach reported to the Vermont Attorney General involving potential Social Security number exposure.