Mortgage Lenders Report Sensitive Data Breaches
Coverage from Morningstar, The Irish Times, and others
Articles
28
Active Days
97
The Topic

Mortgage lenders and related financial organizations are reporting unauthorized access, ransomware activity, and possible theft of sensitive customer or employee information. Exposed data may include Social Security numbers, tax and income records, financial account details, identification data, and account credentials, increasing potential identity-theft and fraud risks. The incidents also show how supplier compromises and delayed notification can extend the impact beyond the initially targeted systems.
First Article: 04/18/26
Latest Article: 07/23/26
Summary
- Plaza Home Mortgage, Optimum First Mortgage, First National Holdings, and Impac Mortgage Holdings reported incidents involving possible access to sensitive personal or financial information.
- Optimum First Mortgage was targeted by the Pear ransomware group, which claimed the attack and threatened to leak data unless payment was made.
- Potentially exposed records include Social Security numbers, tax information, income and employment history, bank account details, driver’s license data, health insurance information, and employee credentials.
- A Pitney Bowes supplier breach put contact details for 137 Revenue Commissioners employees in Ireland at risk, but Revenue said taxpayer data and passwords were not involved.
- Organizations are offering credit monitoring, fraud alerts, and other protective measures while law firms investigate possible claims on behalf of affected individuals.
- The incidents span both newly detected activity and older intrusions disclosed or notified in 2026, complicating assessment of when exposure occurred and how many people were affected.
History
The story now adds a broader set of exposed data types and sharpens the framing around delayed disclosures, making the breach timeline and potential impact more concerning. It also shifts from a simple list of incidents to a clearer picture of supplier risk, ransomware extortion, and older intrusions surfacing later.
The story has shifted from a general pattern of financial-sector breach disclosures to a more specific wave of mortgage-lender incidents, including ransomware, unauthorized access, and supplier compromise. The added reports also sharpen the operational response picture, with notifications, credit-monitoring offers, and legal investigations now central.
