Homebuilding giant Lennar Corp. and its affiliated mortgage subsidiary are seeing the number of potential class action lawsuits surge after revelations this month of two separate data breaches with over 350,000 potential victims.
The rising volume of legal complaints is the latest example of the
"We take seriously the trust our associates, customers and partners place in us. Upon discovery, we acted quickly to secure our systems and engaged leading third-party cybersecurity and digital forensic specialists to investigate the scope and impact of each event," a Lennar spokesperson said.
"There was no operational impact from these events," Lennar continued, while emphasizing it had strengthened security measures against cyber threats.
The breaches are the latest high-profile cybersecurity incidents to strike the mortgage industry this year, following attacks on databases belonging to companies
Similar attacks on mortgage businesses in the past few years, most coming from ransomware or hacker groups, are resulting in a wave of legal settlements in 2026, with corporate actions suggesting companies are willing to resolve consumer lawsuits rather than letting them play out in courtrooms.
Among recent settlements,
In the latest Lennar suit filed earlier this week, Idaho resident Brendan Smedick is pursuing litigation against Lennar Mortgage for the
Smedick seeks to represent a proposed class of approximately 348,416, the number of potentially affected individuals Lennar Mortgage originally reported.
In early June, the lending affiliate discovered an unauthorized outside party had gained access to its data, with the breach lasting for almost a week before preventive measures could be put in place. After a subsequent internal investigation, which was completed early this month, Lennar began notifying possible victims on Aug. 14.
"Lennar Mortgage's lack of security controls and the delayed implementation of enhanced security measures only after the data breach are inexcusable," Smedick's attorneys wrote in their complaint, while also describing the company's practices as falling "below the applicable standard of care."
Since the data breach occurred, Smedick has seen two separate fraudulent or otherwise unauthorized charges appear on his financial accounts, the lawyers wrote in the claim, which in addition to class action status, seeks unspecified monetary damages and a jury trial.
The earlier March incident
In a separate filing, an Arizona resident is seeking recourse against Lennar, not only for the May mortgage breach but also for a different event that struck the parent homebuilder in March.
The total number of affected individuals of the March incident was 6,643, Lennar reported this month, noting that it did not believe the two breaches were connected. The company similarly began advising potential victims in mid-August, with lawyers for plaintiff Wayne Bensfield critical of the more-than-four-month gap between the event and notification.
"Defendants' delay in alerting impacted individuals of the breach prevented plaintiff and class members from taking earlier actions to protect themselves against fraud and misuse of their information," they wrote.
The attorneys also faulted Lennar for alleged shortcomings in internal security protocols.
"Defendants suffered two data breaches in a short period of time, both through social engineering," the document said.
In its August letters, Lennar said it would offer two years of identity-monitoring services to individuals, whose names and information were accessed.





