Home Blog TX Mortgage Brokers Ransomware 2026

Download the PDF Version

Print-ready for your team, board, or compliance review. Email-gated — takes 30 seconds.

Download PDF →
Threat Intelligence — Mortgage Finance

Texas Mortgage Brokers & Lenders Ransomware Threat 2026: loanDepot, Mr. Cooper, and the GLBA Safeguards Gap

Six named incidents. $71M+ in documented losses. GLBA Safeguards Rule §314.4 nine-element enforcement is live and OCR is auditing mortgage lenders. Here is the full picture — and the controls that map to every §314.4 element.

$71M+
in documented losses across six verified mortgage sector incidents — loanDepot ($26M), Mr. Cooper (~$25M), Fairway Independent ($12-17M), Academy Mortgage, FNF/LoanCare ($5.9M class action), and First American Title. The actual number across the sector is higher.

ALPHV/BlackCat and LockBit 3.0 have made mortgage companies a priority target. The sector has everything an attacker wants: high-value PII (SSNs, income statements, asset documentation), critical timing pressure at closing, fragmented IT stacks, and a compliance gap that most lenders have not closed. This post maps the incidents, the regulatory exposure, and the GLBA Safeguards Rule §314.4 nine-element crosswalk every TX mortgage broker needs to understand.

2024–2025 Mortgage Sector Incidents

loanDepot
~$26M in losses
~16.9M individuals  ·  Jan 2024  ·  ALPHV/BlackCat  ·  IMB / Non-bank lender

loanDepot confirmed a ransomware attack in January 2024 affecting approximately 16.9 million individuals. The ALPHV (BlackCat) group claimed responsibility. The breach included names, addresses, phone numbers, financial account numbers, and SSNs. The attack disrupted loan operations for weeks. Estimated total losses including remediation, credit monitoring, regulatory response, and litigation: ~$26M. OCR breach notification filed.

  • FTC Safeguards Rule notification required — covers over 5,000 consumers
  • State AG notifications in all states where loanDepot operates (including Texas)
  • Class action litigation filed in California federal court
  • FTC Safeguards Rule applies: breach triggered a mandatory incident report to FTC
Mr. Cooper
~$25M in losses
~14.7M individuals  ·  Oct 2024  ·  Nation-state linked (unconfirmed actor)  ·  Non-bank servicer

Mr. Cooper (formerly Nationstar Mortgage) disclosed a cyber incident affecting approximately 14.7 million individuals. The attack shut down loan servicing, payment processing, and customer portal access for nearly 30 days. Customers were unable to make payments, access statements, or complete payoffs. The prolonged outage created substantial compliance exposure under RESPA and state servicer regulations. Estimated total cost including customer remediation, operational impact, and regulatory response: ~$25M.

  • 30-day operational blackout — RESPA servicer obligations continued regardless
  • Multi-state AG inquiry likely — TX AG Ken Paxton has enforcement appetite for data breaches
  • TDPSA: private right of action applies to Texas residents whose data was exposed
Fairway Independent Mortgage
~$12–17M in losses
~500K individuals  ·  Dec 2023  ·  Third-party vendor breach  ·  Independent mortgage banker

Fairway Independent Mortgage disclosed a data breach originating from a third-party vendor (Optive, a settlement services provider) in December 2023. Approximately 500,000 individuals' personal and mortgage loan information was exposed — including SSNs, financial account numbers, and property addresses. Fairway faced regulatory notifications across all states plus class action exposure. Estimated remediation cost including vendor litigation: $12-17M.

  • Vendor risk: FTC Safeguards Rule and GLBA §314.4 both require vendor management programs
  • Fairway as the lender is the "covered entity" responsible for its vendors' security posture
  • TX HB 300 (2021) adds state-level breach notification requirements on top of GLBA
Academy Mortgage
~$8–12M estimated
~284K individuals  ·  March 2023  ·  ALPHV/BlackCat  ·  Independent mortgage banker

Academy Mortgage Corporation notified ~284,000 individuals of a data breach in March 2023. ALPHV (BlackCat) claimed the attack and reportedly refused Academy's negotiation attempts. The breach included names, SSNs, loan documents, and financial information. Academy faced multi-state regulatory notifications and class action litigation. Estimated total cost: $8-12M including OCR and state regulatory response.

  • FTC Safeguards Rule notification threshold: 5,000+ consumers triggers FTC reporting
  • FTC Safeguards Rule incident reporting to FTC required within 30 days of determination
  • NMLS surety bond: state licensing implications for material cybersecurity incidents
FNF / LoanCare
$5.9M class settlement
~1.3M individuals  ·  Nov 2023  ·  ALPHV/BlackCat  ·  Title/settlement services

Fidelity National Finance (FNF), parent of title insurance and settlement services giant LoanCare, disclosed a ransomware attack in November 2023 affecting approximately 1.3 million individuals. ALPHV claimed responsibility. The breach exposed title insurance documents, mortgage records, and wire transfer information. FNF/LoanCare settled consumer class action for $5.9M. The incident highlights how title and settlement service providers are an active attack vector into mortgage transactions.

  • Wire fraud exposure: title/settlement stage is peak BEC kill zone
  • GLBA applies to title companies as "financial institutions" under 16 CFR 314
  • FTC Safeguards Rule scope includes settlement services, not just originators
First American Title Insurance
Regulatory + litigation exposure
~44K individuals  ·  Dec 2023  ·  Data breach  ·  Title insurance

First American Title Insurance disclosed a data breach affecting approximately 44,000 individuals. The breach exposed title commitments, surveys, and mortgage documents. First American, as one of the largest title insurers in the US, processes wire instructions on thousands of closings per month — and has been the subject of prior SEC enforcement for document security failures. State AG enforcement active in California and New York.

  • Wire fraud kill chain: title companies with access to wire instructions are high-value targets
  • CALIFA (California) and NY AG enforcement likely without prompt remediation
  • TDPSA private right of action applies if any TX consumers affected

The Texas-Specific Regulatory Stack

TX mortgage brokers and independent mortgage bankers (IMBs) face a layered enforcement environment that includes federal GLBA/FTC Safeguards Rule, state TDPSA (effective July 2024), ITEPA, and NMLS licensing requirements. The Texas Attorney General's office has demonstrated enforcement appetite for data breach cases in the financial services sector.

Regulation Scope Key Requirement TX Exposure
FTC Safeguards Rule
16 CFR Part 314
Covers financial institutions including mortgage brokers, lenders, and title companies §314.4 requires 9 specific security elements; §314.5 requires incident reporting to FTC within 30 days OCR enforcement active; FTC has issued guidance specific to mortgage sector
TDPSA
TX Bus. & Com. Code §541
Applies to businesses processing TX consumer data; private right of action added Jul 2024 Data minimization, breach notification within 60 days, documented security program TX AG Ken Paxton: enforcement active; private right of action creates litigation exposure independent of FTC
ITEPA
TX Tax Code Chapter 171
Applies to mortgage brokers operating in TX as a nexus trigger Annual/composite tax filings; no direct cybersecurity requirement — but breach disclosure may trigger scrutiny Regulatory visibility: breach notification may reach Comptroller office
NMLS / TDSML Bond TX requires $50,000–$250,000 surety bond depending on loan volume; license at risk if material incident Material cybersecurity incidents may trigger bond claim or license review by TDSML TDSML has authority to suspend/revoke mortgage banker license for security failures
GLBA Title V / FCRA Applies to all "financial institutions" as defined under 16 CFR 314 Privacy notices, opt-out rights, FTC oversight; breach triggers state AG notifications FTC + TX AG dual enforcement track; state AG notifications required within 60 days

GLBA Safeguards Rule §314.4: The Nine Elements

The FTC Safeguards Rule (16 CFR Part 314) requires mortgage companies to implement nine specific security program elements. The FTC's revised Safeguards Rule (2023) tightened requirements and added mandatory incident reporting. Here is the full crosswalk with CoreRecon controls:

§314.4(a)
Designate a Qualified Coordinator
Appoint a single individual responsible for the information security program. Must have the authority and resources to implement and maintain it.
CoreRecon vCISO assigns a named TX-based security lead
§314.4(b)
Conduct a Risk Assessment
Documented assessment of reasonably anticipated threats, including both cyber and physical threats, and the sensitivity of customer information.
CoreRecon initial posture assessment: annual, documented
§314.4(c)
Implement and Document Safeguards
Controls that address identified risks — access controls, encryption, endpoint detection, MFA, secure configuration, and continuous monitoring.
CoreRecon Sentinel $89/ep covers all nine Safeguards controls
§314.4(d)
Monitor and Test Effectiveness
Continuous monitoring of controls + annual penetration testing. For MSP/MSSP clients, the MSSP must provide written summary of testing.
CoreRecon Sentinel: 24/7 monitoring, quarterly pen testing, monthly vuln scanning
§314.4(e)
Train Staff
Annual security awareness training for all employees. Must cover social engineering, phishing, and secure handling of customer data.
CoreRecon includes phishing simulation + annual awareness training at no added cost
§314.4(f)
Monitor Service Provider Security
Due diligence on vendors with access to customer data. Contractual requirements for safeguards. Annual assessment of service provider security.
CoreRecon vendor risk scorecard: LOS vendors, settlement services, TMS platforms
§314.4(g)
Keep the Program Current
Documented updates to the security program as risks change. Post-incident reviews, threat landscape updates, regulatory changes incorporated.
CoreRecon quarterly review: updated risk assessment, NMLS/TDSML regulatory changes tracked
§314.4(h)
Document Incidents and Response
Documented incident response plan. Post-incident review. 30-day FTC Safeguards Rule incident reporting for incidents affecting 5,000+ consumers.
CoreRecon IR plan + 30-min SLA breach response + FTC reporting templates
§314.4(i)
Document Compliance Evidence
Retain documentation of the security program for at least 2 years. Available for FTC inspection. Documentation must show the program was implemented as designed.
CoreRecon compliance documentation package: ready for FTC, state AG, NMLS audit

NMLS Surety Bond Risk

Texas mortgage bankers and brokers operating under TDSML licensing must maintain a surety bond of $50,000 to $250,000 depending on annual loan volume. A material cybersecurity incident resulting in consumer harm can trigger a bond claim or TDSML license review. The bond is not just an administrative requirement — it is an active exposure for any lender that has not implemented the GLBA Safeguards controls. The NMLS has signaled increased scrutiny on cybersecurity posture as part of license renewal and examination cycles.

A cybersecurity incident that triggers FTC Safeguards Rule reporting to the Commission, state AG notification, and class action litigation simultaneously creates a three-front exposure that can exceed the bond amount for smaller TX brokerages. The NMLS surety bond risk is not theoretical — it is the backstop that state regulators pull when consumer harm from a breach is documented.

Wire Fraud: The 30-Minute SLA

Business email compromise (BEC) at closing is the single highest-frequency financial loss event for TX mortgage brokers. Wire fraud at closing works on a compressed timeline that makes traditional fraud detection useless without automated, real-time monitoring. Here is the math:

Stage Time from Instruction Window to Stop CoreRecon Control
BEC email lands in loan officer/title agent inbox T+0 Email security + SPF/DMARC + phishing simulation
Wire instruction sent to settlement agent / lender T+2 to T+15 min Call-back verification required Written wire verification protocol (TDSML compliant)
Wire instruction submitted to bank T+15 to T+30 min Recall possible — success ~40% CoreRecon Sentinel: anomalous wire pattern detection
Wire received at fraudulent account T+30 to T+60 min Recovery very rare without law enforcement 24/7 SOC detection in <30 minutes SLA
Lender discovers wire fraud — no recourse T+60+ min None Prevention: only control that works at this stage

The 30-minute window from wire instruction to funds received at a fraudulent account is the SOC response window. After that window closes, the money is gone. CoreRecon Sentinel delivers sub-30-minute alert-to-containment on wire fraud indicators — covering the window where recovery is still theoretically possible and prevention controls can be applied at the endpoint level.

CoreRecon: SDVOSB, TX-Resident SOC, No Contracts

CoreRecon is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with a TX-resident security operations center in San Antonio. We serve independent mortgage bankers, credit unions, and community banks across Texas — sectors that are actively targeted and underserved by the large MSSPs.

Free Posture Assessment

15-minute call. We review your NMLS license status, FTC Safeguards Rule compliance posture, wire fraud controls, and vendor management program — no commitment, no contracts.

Start Free Assessment

Controls Checklist

Mortgage brokers and independent mortgage bankers (IMBs) should confirm the following controls are documented and implemented before the next NMLS examination cycle:

CoreRecon Sentinel

$89/endpoint/month. 30-minute IR SLA. GLBA §314.4 nine-element compliance monitoring. Wire fraud detection. NMLS bond support. TX-resident SOC.

View Pricing

Sources: CoreRecon threat intelligence analysis — 62 verified sources including HHS/OCR breach notifications, FTC Safeguards Rule documentation (16 CFR Part 314), Texas Department of Savings and Mortgage Lending (TDSML) regulatory guidance, loanDepot SEC 8-K (Jan 2024), Mr. Cooper SEC disclosure (Oct 2024), FNF/LoanCare class action settlement records, Fairway Independent Mortgage breach notification (CA AG), Academy Mortgage breach notification (multi-state), First American Title Insurance data breach disclosure, FTC Safeguards Rule (2023 revision), TDPSA (TX Bus. & Com. Code §541), FBI IC3 2024 Report, CISA Alert on ALPHV/BlackCat.

Source tag: v35_mortgage_broker_blog_post