Impac Mortgage Holdings: Lawsuit accuses Impac Mortgage of waiting two years to disclose borrower data breach

Impac Mortgage Holdings: Lawsuit accuses Impac Mortgage of waiting two years to disclose borrower data breach

Impac Mortgage Faces Class Action Over Delayed Data Breach Notification

A proposed nationwide class action lawsuit has been filed against Impac Mortgage Holdings, a residential mortgage lender based in Irvine, California, alleging negligence and delayed response following a data breach. The suit, led by plaintiff Monica P. Espejo of Anaheim, claims the company failed to implement adequate safeguards, including encryption and intrusion detection systems, to protect borrower data.

The breach was first detected nearly two years before affected individuals were notified with letters mailed on March 27, 2026, according to court filings. The lawsuit estimates thousands of U.S. consumers were impacted, with damages exceeding $5 million under the Class Action Fairness Act. Legal claims include negligence, breach of implied contract, and violations of Section 5 of the Federal Trade Commission Act, which mandates timely breach response protocols.

The case highlights growing scrutiny over lender data security practices, particularly the timing of breach notifications under state laws and the Gramm-Leach-Bliley Safeguards Rule. If a jury finds the two-year delay unreasonable, it could set a precedent for how plaintiffs’ attorneys approach future lender breaches.

Impac has not yet responded to the allegations, and no court rulings have been issued. The company did not provide comment at the time of publication.

Source: https://www.mpamag.com/us/mortgage-industry/industry-trends/lawsuit-accuses-impac-mortgage-of-waiting-two-years-to-disclose-borrower-data-breach/573352

Impac Mortgage Corp. cybersecurity rating report: https://www.rankiteo.com/company/impacmortgage

"id": "IMP1777415218",
"linkid": "impacmortgage",
"type": "Breach",
"date": "3/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Thousands of U.S. consumers',
                        'industry': 'Financial Services',
                        'location': 'Irvine, California, USA',
                        'name': 'Impac Mortgage Holdings',
                        'type': 'Residential mortgage lender'}],
 'customer_advisories': 'Letters mailed to affected individuals on March 27, '
                        '2026',
 'data_breach': {'data_encryption': 'Lack of encryption',
                 'type_of_data_compromised': 'Borrower data'},
 'date_publicly_disclosed': '2026-03-27',
 'description': 'A proposed nationwide class action lawsuit has been filed '
                'against Impac Mortgage Holdings, alleging negligence and '
                'delayed response following a data breach. The company is '
                'accused of failing to implement adequate safeguards, '
                'including encryption and intrusion detection systems, to '
                'protect borrower data. The breach was detected nearly two '
                'years before affected individuals were notified.',
 'impact': {'data_compromised': 'Borrower data',
            'financial_loss': '$5 million (estimated damages under Class '
                              'Action Fairness Act)',
            'legal_liabilities': 'Negligence, breach of implied contract, '
                                 'violations of Section 5 of the Federal Trade '
                                 'Commission Act'},
 'post_incident_analysis': {'root_causes': 'Lack of adequate safeguards '
                                           '(encryption, intrusion detection '
                                           'systems)'},
 'references': [{'source': 'Court filings'}],
 'regulatory_compliance': {'legal_actions': 'Class action lawsuit filed',
                           'regulations_violated': ['Gramm-Leach-Bliley '
                                                    'Safeguards Rule',
                                                    'Section 5 of the Federal '
                                                    'Trade Commission Act']},
 'response': {'communication_strategy': 'Delayed notification (letters mailed '
                                        'on March 27, 2026)'},
 'title': 'Impac Mortgage Data Breach and Delayed Notification',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Lack of encryption and intrusion detection '
                            'systems'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.