A recent hack at a mortgage lender is showing how cybercriminals are interested in a company's vendor data and trade secrets in addition to sensitive customer information.
The ransomware gang known as Interlock claims it seized over 2 terabytes of data earlier this month from
In a statement Wednesday evening, the company's legal department acknowledged a cybersecurity incident but did not share additional details, and said it cannot confirm the number of people impacted. NFM said it took immediate action to safeguard its systems with the assistance of a third-party forensics team.
"The security of our systems is a top priority for us, and we are taking this matter seriously," the statement read. "We are following all protocols to ensure compliance with notification and credit protection resources for anyone impacted."
A consumer filed a class action lawsuit against NFM last week following reports of the incident, a complaint analogous to the many suits filed against companies following news of a breach. The lawsuit in a Maryland federal court against NFM was first reported by Claim Depot.
Former NFM customer Sheneka Smith says NFM hasn't notified customers of an incident, and argues that the lender failed to maintain reasonable safeguards for its systems. The company in its statement suggested the case and other similar suits are "designed to revictimize organizations" and that it would not be a distraction to its investigation.
The Maryland-based NFM has over 600 sponsored mortgage loan originators and generated over $7.2 billion loan volume last year, according to publicly available data.
Lenders seldom reveal the details of a data breach, although threat actors have
Another lender reveals a data breach
Pittsburgh-based Affordable Mortgage Advisors, which does business under the HMA Mortgage brand, also disclosed last week a hack affecting an untold number of individuals.
An unauthorized party accessed the company's systems between July and September 2025, according to a notice shared by HMA. The lender said in its notice posted on its website that it has no indication any fraudulent activity stemmed from the incident.
A spokesperson for HMA said the company had no comment Wednesday. The lender didn't respond to a question whether an incident it previously reported as occurring February 2025 and affecting 3,025 individuals was related to the new notice.
The company has 176 sponsored MLOs and 28 branches across the country, and reported $1.2 billion in loan origination volume last year, according to public databases.
NFM and HMA are the latest lenders to report data breaches this year as tens of thousands of real estate customers have been affected by more recent incidents. More lenders in recent months have also moved








