theLender Data Breach Exposes Customer Personal and Financial Information

Published: 22 September 2026
Finance data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: Not Publicly Disclosed

theLender, a US wholesale mortgage company, was hit by a ransomware attack claimed by the Termite group, raising concern that borrower and employee personal and financial data was accessed. The exact number affected has not been disclosed. Anyone connected to theLender should monitor credit reports and financial statements for suspicious activity right away.

CompanytheLender
IndustryFinance
Data Types ExposedFull Names and Contact Information, Social Security Numbers, Financial Account Details, Loan Application and Underwriting Documents, Employment and Income Information, Property and Mortgage Records
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the theLender Data Breach?

theLender, a wholesale mortgage lender operating in the United States, has confirmed it was the target of a ransomware attack. A group known as Termite has claimed responsibility for breaching the company’s network. This kind of attack typically involves gaining unauthorized entry into internal systems before locking or stealing files.

Details about the exact timeline remain limited. The breach discovery date has not been publicly disclosed, and neither has the notification date. However, ransomware groups like Termite are known for a consistent pattern: they infiltrate a network quietly, extract sensitive files, and later threaten to publish stolen data unless a ransom gets paid.

As a result, this incident fits the profile of a data theft event rather than a simple system outage. Because Termite has publicly claimed the attack, there is credible evidence that the group accessed theLender’s systems. An investigation into the scope of the intrusion is presumably underway, though further forensic findings have not yet been made public.

In response to attacks like this, companies typically bring in outside cybersecurity specialists to determine what was accessed and how. theLender has not yet released a detailed public statement describing the full extent of the compromise. Affected individuals should watch for official notification letters in the coming weeks.

Who was affected?

The individuals affected by this theLender data breach likely include mortgage customers whose loan applications and financial records were stored in the company’s systems. Because theLender operates as a wholesale mortgage lender, its data may also include information tied to mortgage brokers and partner institutions.

The exact number of affected individuals has not been publicly disclosed. Therefore, it is not yet possible to say how many people are impacted or exactly where they are located. Given the company’s national scope within the US wholesale mortgage industry, the affected population could span multiple states.

In addition, employees of theLender could also be among those affected if internal personnel records were stored on the compromised systems. Mortgage transactions often involve highly sensitive documentation. This means both borrowers and possibly co-borrowers connected to loan files could be at risk.

What Information Was Potentially Exposed?

Because theLender processes wholesale mortgage loans, the type of data it typically handles is highly sensitive. While the company has not released a complete list of compromised data categories, the nature of its business suggests the following types of information could be at risk.

  • Full names and contact information
  • Social Security numbers
  • Financial account details
  • Loan application and underwriting documents
  • Employment and income information
  • Property and mortgage records

If Social Security numbers and financial account details were indeed exposed, affected individuals could face a heightened risk of identity theft. Criminals often use this kind of stolen data to open fraudulent credit accounts or file false tax returns. As a result, victims may not notice the misuse right away.

Moreover, mortgage-related documents often include income verification and property details. This combination of data could allow scammers to impersonate victims when applying for loans or lines of credit. Because mortgage fraud can take months to detect, affected individuals should stay alert for unusual account activity for an extended period.

What is the company doing?

Following discovery of the intrusion, theLender presumably launched an internal investigation to assess the scope of the breach. Companies facing ransomware attacks typically isolate affected systems, engage forensic experts, and work to determine which data files were accessed or stolen.

At this time, theLender has not publicly detailed specific remediation steps, such as offering credit monitoring or identity protection services. However, companies that experience confirmed data theft in similar circumstances often provide these protective services to impacted individuals once the investigation concludes. Affected individuals should watch for formal notification letters that typically outline next steps and any available protections.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone connected to theLender, whether as a borrower, co-borrower, or employee, should begin monitoring their credit reports closely. Regularly reviewing your credit file can help you catch suspicious new accounts or inquiries before they cause serious damage.

You can request free credit reports from each of the three major credit bureaus. Because mortgage data often includes detailed financial history, checking your reports every few months for the next year is a reasonable precaution.

Consider a Fraud Alert or Credit Freeze

If Social Security numbers or financial account information were part of this breach, placing a fraud alert on your credit file is a smart step. A fraud alert requires lenders to verify your identity before opening new credit in your name.

For stronger protection, you can also request a credit freeze with each bureau. This makes it much harder for identity thieves to open new accounts using your information. While a freeze takes a few extra steps when you need to apply for credit yourself, it offers significant peace of mind.

Watch for Phishing and Scam Attempts

After a data breach, scammers often send emails or texts pretending to be from the breached company. These messages may ask you to click a link or provide personal details to “verify your account.”

Because theLender deals with mortgage loans, be especially cautious of messages referencing loan payments, refinancing offers, or account verification requests. Never click links or provide personal information unless you can confirm the request is legitimate by contacting theLender directly through a verified phone number.

Review Mortgage and Financial Statements Carefully

Given the sensitive nature of mortgage-related data, affected individuals should carefully review any mortgage statements, escrow account activity, and related financial documents. Unexpected changes could indicate fraudulent activity connected to the breach.

If you notice unfamiliar account changes or unauthorized inquiries tied to your mortgage, contact your loan servicer immediately. In addition, consider speaking with a data breach attorney to understand whether you may be eligible for compensation through a potential class action related to this incident.

Keep Records of Any Suspicious Activity

If you notice any signs of identity theft or fraud following this breach, document everything carefully. Keep copies of suspicious emails, unfamiliar account statements, and any correspondence with financial institutions.

This documentation can prove valuable if you need to file a report with the Federal Trade Commission or pursue legal action. Consulting with a data breach attorney can also help you understand your rights and options for a free case evaluation.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

View the full list of tracked data breaches →