Lennar Data Breach Exposes Sensitive Information of Over 60,000 Texans
Homebuilder Lennar Corporation disclosed a data breach involving unauthorized access to its systems between May 26 and June 1, 2024, following a sophisticated social engineering attack. The incident, confirmed in notices posted by Texas Attorney General Ken Paxton and the California Department of Justice, affected 60,526 Texans, with potential exposure of personal and financial data.
Lennar completed its assessment on August 4, revealing that compromised information may include names, contact details, dates of birth, Social Security numbers, government-issued IDs (passports, driver’s licenses), and financial account data. A small subset of individuals may have also had medical-related information exposed, though not all affected parties had every category of data impacted.
The company stated it has no evidence of misuse of the stolen information but has engaged Kroll, a global risk advisory firm, to provide two years of complimentary identity monitoring for affected individuals. Those impacted have until November 20, 2026, to activate the service.
Lennar’s notice advised affected individuals to monitor account statements and credit reports for suspicious activity and provided guidance on placing fraud alerts and credit freezes with major credit bureaus. The company did not respond to requests for further comment at the time of publication.
Source: https://www.housingwire.com/articles/lennar-mortgage-data-security/
Lennar cybersecurity rating report: https://www.rankiteo.com/company/lennar
"id": "LEN1787070397",
"linkid": "lennar",
"type": "Breach",
"date": "5/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '60526',
'industry': 'Homebuilding',
'location': 'United States',
'name': 'Lennar Corporation',
'type': 'Corporation'}],
'attack_vector': 'Social Engineering',
'customer_advisories': 'Affected individuals advised to monitor accounts and '
'activate identity monitoring services.',
'data_breach': {'number_of_records_exposed': '60526',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Names',
'Contact details',
'Dates of birth',
'Social Security numbers',
'Government-issued IDs '
'(passports, driver’s licenses)',
'Financial account data',
'Medical-related information']},
'date_detected': '2024-06-01',
'date_resolved': '2024-08-04',
'description': 'Homebuilder Lennar Corporation disclosed a data breach '
'involving unauthorized access to its systems between May 26 '
'and June 1, 2024, following a sophisticated social '
'engineering attack. The incident affected 60,526 Texans, with '
'potential exposure of personal and financial data.',
'impact': {'data_compromised': 'Personal and financial data',
'identity_theft_risk': 'High',
'payment_information_risk': 'High'},
'investigation_status': 'Completed',
'post_incident_analysis': {'root_causes': 'Sophisticated social engineering '
'attack'},
'recommendations': 'Monitor account statements and credit reports for '
'suspicious activity; place fraud alerts and credit '
'freezes with major credit bureaus.',
'references': [{'source': 'Texas Attorney General Ken Paxton'},
{'source': 'California Department of Justice'}],
'regulatory_compliance': {'regulatory_notifications': ['Texas Attorney '
'General',
'California Department '
'of Justice']},
'response': {'communication_strategy': 'Notices posted by Texas Attorney '
'General and California Department of '
'Justice',
'enhanced_monitoring': 'Two years of complimentary identity '
'monitoring',
'third_party_assistance': 'Kroll'},
'title': 'Lennar Data Breach Exposes Sensitive Information of Over 60,000 '
'Texans',
'type': 'Data Breach'}