California penalizes Academy Mortgage over 2023 data breach

Academy Mortgage agreed to a consent order with California regulators that penalizes the lender and finds fault with its information technology procedures and oversight, which allegedly contributed to a 2023 data breach.

Processing Content

In resolving the case, Academy Mortgage, which has ceased all origination and servicing activity, agreed to pay $825,000 to the state's Department of Financial Protection and Innovation. The incident put the personally identifiable information of 284,443 individuals at risk, including 34,452 residents of the Golden State, according to DFPI. 

"Companies that have access to our personal information must have robust, stringent cybersecurity," said DFPI Commissioner KC Mohseni in a press release.

"This penalty should act as a deterrent to companies — strong data protection for Californians is non-negotiable." 

In addition to the financial penalty, Academy will also be required to offer free identity-theft insurance coverage to affected customers for 12 months.  

The timeline of events

Hackers first infiltrated Academy's data network in mid-March 2023, installing malware and gaining access to credentials that allowed them to disable security systems, according to the consent order. The breach was contained a week later. Cybercriminal group AlphV, or Black Cat, later took credit for a ransomware attack

An initial third-party investigation took place in the two months following the incident, with further internal review conducted in the fourth quarter of 2023. Academy did not start notifying customers of their compromised data until December that year. Customers would accuse the Draper, Utah-based lender of dragging its feet in providing them with details in ensuing consumer legal action filed against the company. 

In its investigation, California officials found serious deficiencies in Academy's operations, particularly in regard to information security, recordkeeping and governance, which opened the door to the 2023 hack. The consent order included sharp criticism on the part of DFPI over the lender's lax cybersecurity measures. 

"Academy did not maintain a documented asset inventory of its computer systems and data, an up-to-date incident-response plan, documentation of tracking and follow-up on audit findings or written IT policies and procedures for multiple issue areas," the document said. 

Between 2017 and 2023, Academy did not conduct a comprehensive formal audit of its information security program, according to DFPI. The department also determined the company neglected to perform a sufficient number of security risk assessments in the two years leading up to the cyber incident and found deficient vulnerability and patch management protocols. 

The consent order specifically called out Academy's board of directors for lapses in oversight and planning of business operations as well. 

"Respondent represented to the department that it carried out appropriate day-to-day information security practices but did not document these actual practices in its policies and procedures," DFPI wrote. 

Academy's records were in such a state that examiners could not conclude whether the company was in compliance with state mortgage regulations, the document also said. 

Regarding the data incident, the California regulator claimed Academy neglected to obtain a written forensic report to adequately document the breach, resulting in limited transparency about the event.

In late February 2024, just days prior to commencement of the commissioner's examination, Academy sold its entire retail lending operations to Guild Mortgage. It ceased originations of new mortgages in March of that year. 

The consent order carries with it neither admission nor denial of the department's conclusions. Lawyers representing Academy's parent company did not respond to an inquiry from National Mortgage News prior to publication. A Guild Mortgage representative declined to comment.  

California boosts enforcement as feds pull back

The resolution comes as the focus on consumer protection laws and enforcement turn to U.S. states amid a loosening federal regulatory environment. California ranks high on the list of states the financial services industry and attorneys are eyeing, due to its reputation for strict oversight and the large number of consumers its regulations cover.   

California was one of several states to reach a settlement with E Mortgage Capital in 2025 after regulators alleged the company had engaged in unlicensed lending activity across the country. Earlier this year, Fairway Home Mortgage also resolved a case with DFPI following similar accusations.

In July, Gov. Gavin Newsom, D-Calif., officially appointed former Consumer Financial Protection Bureau Director Rohit Chopra, who was frequently criticized for regulatory overreach during his tenure under former President Biden, to serve in his administration. Chopra now holds the title of secretary in the newly created California business and consumer services agency.

Academy is the latest in a line of mortgage companies that have recently agreed to settle cases in order to resolve lawsuits or regulatory enforcement after a spate of cyberattacks this decade. In the largest settlement in recent history, Bayview Asset Management will pay $26 million following a massive attack across its servicing units in 2021. 


For reprint and licensing requests for this article, click here.
Regulation and compliance Law and legal issues Mortgage fraud Cyber Security
MORE FROM NATIONAL MORTGAGE NEWS
Load More