LoanDepot is facing the aftermath of a serious data breach, with the sensitive personal information of 16.6 million customers accessed in an early-January cyberattack that bears the hallmarks of a ransomware extortion attack.
The U.S. mortgage and loan giant did not specify the type of data that was stolen. However, in its latest cybersecurity incident update on Monday, LoanDepot said “an unauthorized third party gained access to sensitive personal information of approximately 16.6 million individuals” in its computer systems.
An early-January filing with the United States Securities and Exchange Commission (SEC) revealed more: “..the unauthorized third party activity included access to certain Company systems and the encryption of data.” This encryption of data mentioned here is typical of ransomware attacks.
“In response, the Company shut down certain systems and continues to implement measures to secure its business operations, bring systems back online and respond to the incident,” the filings added.
LoanDepot Customers Locked Out
In the past week, local Irvine, California news outlets added that customers were unable to make payments or access their online accounts. On Monday, however, the company said it has “made significant progress,” in restoring systems like its loan origination and loan servicing, including its “Servicing” and “MyloanDept” customer portals.
“Unfortunately, we live in a world where these types of attacks are increasingly frequent and sophisticated, and our industry has not been spared. We sincerely regret any impact to our customers,” LoanDepot’s CEO Frank Martell said in a company update on Monday.
LoanDepot said that it is actively working with external forensics and security experts to investigate the incident and restore normal operations.
Throughout this period, LoanDepot focused on supporting affected customers by offering credit monitoring and identity protection services, while continuously updating the public and stakeholders on their recovery progress and the ongoing investigation.
Significant Ransomware Attack Occurred in Early January
LoanDepot experienced a significant cyberattack on January 8, 2024, which led to the unauthorized access and compromise of the sensitive personal information of approximately 16.6 million customers. The attack comes in the wake of earlier incidents that hit insurance, mortgage and loan establishments like the Nov. 2023 Fidelity National Financial and Oct. 2023 Mr. Cooper cyberattacks.
By January 18, LoanDepot had begun restoring key customer portals, including their servicing customer portal, HELOC (Home Equity Line of Credit) portal, and the “MyLoanDepot” customer portal for online applications and status tracking.
Despite these efforts, the incident led to a class-action lawsuit filed by a customer on Jan. 19, alleging negligence and other charges, HousingWire reported on Monday. Furthermore, following the data breach, a customer encountered a notable uptick in spam phone calls and text messages. The customer also observed unfamiliar information and accounts appearing on her credit report, which she suspects are linked to the data breach incident.
“The Company will notify these individuals and offer credit monitoring and identity protection services at no cost to them,” the company’s latest statement reads.
Are You a LoanDepot Customer? Secure Your Data Now
The recent data breaches in the financial sector are not limited to LoanDepot. A report from 2022 indicates that over 360 million people were affected by data breaches in just the first eight months of the year. This study describes data breaches as an “epidemic,” with a 70% increase in ransomware attacks and the alarming use of generative AI by cybercriminals.
Additionally, the genetic testing company 23andMe faced a significant data breach in Oct. 2023, leading to a class-action lawsuit. The breach, which exposed the personal details of possibly millions of users, was attributed to credential stuffing attacks.
If you’re one of the LoanDepot customers potentially impacted by the recent data breach, it’s crucial to take immediate steps to secure your personal information.
Check out LifeLock
This breach may have exposed your sensitive data, such as personal identification details and financial information. Therefore, vigilance is key in monitoring your financial accounts for any unauthorized transactions. We highly recommend using unique and strong passwords across your accounts, as well as two-factor authentication. Remember, never repeat a password across more than one account.
Read our Lifelock Identity Theft Protection review, a comprehensive identity theft monitoring and cybersecurity package.
Furthermore, be aware that compromised information can sometimes end up on the dark web, making it accessible to malicious actors. We recommend you use the Have I Been Pwned data breach notification service to check for exposed credentials.
NordPass password manager can also check if your credit information was leaked online.
For more news, follow us on X (Twitter), Threads, and Mastodon!
