The silence after the breach is the part you control

14 hours ago 3

A ransomware group posts a lender’s name on a dark web leak site. Terabytes of loan files, Social Security numbers, bank account details, employee records. The clock the public sees starts there. The clock that matters started weeks or months earlier, the day the intrusion was detected. And in the gap between those two moments, while the company says nothing, the most damaging part of the event is already underway. The mortgage industry has a breach problem. Since January, at least five nonbank lenders have disclosed prior hacks. One Long Island lender detected unauthorized network activity in May 2025 and did not notify affected employees until March 2026, a delay a subsequent lawsuit puts at more than 260 days past the statutory deadline. These are not outliers. They are the pattern. But the breach itself is not the story worth telling. Lenders will keep getting attacked, because lenders hold exactly what attackers want. The story is what happens in the silence afterward, and how much of that silence is a choice. The long tail of a loan file Start with what makes mortgage data uniquely toxic when it leaks. Lenders retain records for decades. When one large servicer was breached, ...

Read Entire Article