Last Update: 08/01/2026 at 2:00 PM EST

Mortgage Lenders Report Sensitive Data Breaches

Coverage from Morningstar, The Irish Times, and others

Articles

28

Active Days

97

The Topic

Mortgage Lenders Report Sensitive Data Breaches topic image

Mortgage lenders and related financial organizations are reporting unauthorized access, ransomware activity, and possible theft of sensitive customer or employee information. Exposed data may include Social Security numbers, tax and income records, financial account details, identification data, and account credentials, increasing potential identity-theft and fraud risks. The incidents also show how supplier compromises and delayed notification can extend the impact beyond the initially targeted systems.

First Article: 04/18/26

Latest Article: 07/23/26

History

07/23/20261 new articles

The story now adds a broader set of exposed data types and sharpens the framing around delayed disclosures, making the breach timeline and potential impact more concerning. It also shifts from a simple list of incidents to a clearer picture of supplier risk, ransomware extortion, and older intrusions surfacing later.

07/22/20260 new articles

The story has shifted from a general pattern of financial-sector breach disclosures to a more specific wave of mortgage-lender incidents, including ransomware, unauthorized access, and supplier compromise. The added reports also sharpen the operational response picture, with notifications, credit-monitoring offers, and legal investigations now central.

  • Plaza Home Mortgage reported unauthorized access affecting up to 137,976 people.
  • Optimum First Mortgage faced a ransomware claim from Pear.
  • Pitney Bowes supplier breach risked Revenue staff contact details.
  • Impac began notifying individuals in 2026 after 2024 unauthorized access.
  • Legal investigations now include Plaza Home Mortgage and Optimum First Mortgage.
07/21/20266 new articles

The story has broadened from mortgage-lender breaches to a wider set of financial-services and insurance disclosures, with more explicit emphasis on third-party access, health-related data, and class-action responses. Delayed notice remains central, but the current version adds new companies, new jurisdictions, and stronger litigation framing.

  • SoFi Hong Kong reported third-party vendor access exposure.
  • Markel Insurance disclosed personal and protected health information exposure.
  • First National Holdings notified affected people about identity, financial, and health insurance data.
  • Wolf Haldenstein Adler Freeman & Herz LLP joined breach investigations.
  • Coverage now spans the United States and Hong Kong in addition to Ireland.
06/21/20263 new articles

The story broadens beyond mortgage breaches into a wider consumer-finance and insurance pattern, with new companies and vendor-linked incidents entering the cluster. The updated framing also sharpens the emphasis on identity-data exposure, notification delays, and litigation review across a larger set of firms.

06/13/20263 new articles

The cluster is now framed more explicitly as a recurring mortgage and financial-services privacy-risk pattern, with stronger emphasis on delayed notice, litigation scrutiny, and vendor/employee access pathways. The biggest substantive addition is the clearer extension beyond mortgage lenders into fintech and insurance incidents.

06/11/20263 new articles

The story broadened from a mortgage-breach cluster into a wider mortgage, fintech, and insurance privacy pattern, with new cases and regulators added. The latest version also places more emphasis on delayed disclosures and vendor-access weaknesses as recurring themes.

06/04/20263 new articles

The story broadens from a mortgage-breach pattern into a denser cluster that now includes Plaza Home Mortgage, Industrial Acceptance, and more explicit consumer remediation and litigation activity. The most important new emphasis is that delayed disclosure and employee/internal-system access are now central themes, not just supporting details.

05/30/2026Topic Formed

Recent material shows repeated mortgage and financial-services breach disclosures involving names and Social Security numbers, delayed notification timelines, and active law-firm investigations into class action claims. A related supply-chain breach reinforces vendor-access risk in financial data handling.