• 4 minuti
  • Pubblicato

NFM Lending hit by huge data breach claim after Interlock ransomware attack

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

NFM Lending hit by huge data breach claim after Interlock ransomware attack QWERTYmag © www.qwertymag.it
NFM Lending hit by huge data breach claim after Interlock ransomware attack © www.qwertymag.it

A ransomware group says it stole over 2.5 terabytes of data from NFM Lending, including Social Security numbers and financial records. The breach has triggered a class action lawsuit and urgent questions about the lender's cybersecurity.

NFM Lending is facing claims of a major data breach after the ransomware group Interlock said it stole more than 2.5 terabytes of sensitive files from the company. The fallout was quick. A proposed class action lawsuit now accuses NFM of failing to protect customer and employee data and of keeping those affected in the dark.

Industry reports say the breach likely happened around September 7, 2026. Interlock claims it got access to a huge amount of information, including Social Security numbers, financial account details, and internal files like Encompass mortgage documents. Both customer and employee data are reportedly involved. The attackers say they took over 2 TB of files. That's a massive amount for a single financial sector breach and raises questions about how many systems were hit and the risk of fraud down the line.

NFM Lending has confirmed the cyber incident. The company brought in a third-party forensic team and says it took immediate steps to protect its systems. But NFM has not said how many people were affected or revealed the full scope of the breach. This lack of detail stands out, especially given rules in the U.S. and Europe-like the GDPR and Italian Garante Privacy guidelines-that require quick notification and risk control for people whose data is at risk.

On September 16, Sheneka Smith filed a proposed class action in the U.S. District Court for the District of Maryland. She says NFM Lending customers had their names, Social Security numbers, and financial records exposed. The complaint, reviewed by HousingWire, points to a key failure: as of the filing, NFM had not told customers about the breach. That left them unable to freeze credit or watch for fraud. The lawsuit claims negligence, breach of implied contract, unjust enrichment, and violations of the Maryland Consumer Protection Act.

Nel contesto delle recenti violazioni, il Garante Privacy ribadisce che le aziende finanziarie devono adottare misure tecniche e organizzative adeguate, in linea con le raccomandazioni ENISA e le direttive europee, per garantire la sicurezza dei dati personali e la tempestiva comunicazione agli interessati in caso di data breach.

Garante per la Protezione dei Dati PersonaliAutorità italiana per la privacy

Smith's lawsuit goes further. It says NFM Lending ignored basic cybersecurity practices. The suit claims the company failed to train staff properly and did not put reasonable security measures in place. It points to industry standards like the NIST Cybersecurity Framework 2.0, CIS Critical Security Controls, and FTC data protection guidelines. These are widely used in the U.S. and EU to set the baseline for risk management, incident response, and employee training.

NFM Lending says it "takes this matter seriously" and is focused on system security. The company says it is following notification and credit protection steps for those affected. But as of the lawsuit's filing, many customers still had not been told. This gap between policy and action has drawn attention from regulators, including the Italian Garante Privacy and the Agenzia per la Cybersicurezza Nazionale (ACN). Both have recently issued warnings about ransomware and the need to notify people quickly after a breach. For more on what regulators expect, see the Garante Privacy official guidance.

This breach comes as the financial sector is already dealing with a wave of cyberattacks and lawsuits. As reported earlier, companies hit by big data leaks are facing more lawsuits and regulatory scrutiny. Customer trust and company reputations are on the line.

Implications and outlook

The Interlock breach claim against NFM Lending shows that even established lenders can get caught off guard by ransomware groups. The alleged failure to notify customers and claims of weak internal controls point to more than just technical problems. They show a lack of crisis planning. With data now so valuable, lenders who skip on cybersecurity and clear communication risk lawsuits and lasting damage to their reputation. The industry can't treat data protection as an afterthought. This case shows the cost of ignoring it is only going up.

Articoli correlati