NFM Lending Investigates Alleged Data Breach After Hacker Group Claims 2.5TB Leak
On September 7, 2026, the hacker group Interlock claimed responsibility for a suspected ransomware attack on NFM Lending, a Maryland-based residential mortgage lender operating in 49 states. The group alleged the breach exposed over 2.5 terabytes of sensitive data, including names, Social Security numbers, financial details, loan terms, addresses, and contact information belonging to more than 1 million clients and employees.
Dark web monitoring sites, including Ransomware.live, reported the incident, though NFM Lending has not confirmed the breach’s scope or authenticity. Legal teams are now investigating whether a class action lawsuit can be filed on behalf of affected individuals, including current and former clients and employees. Potential claims may seek compensation for privacy violations, financial losses, and other damages.
As of September 9, 2026, no further details about the breach’s nature or NFM Lending’s response have been disclosed. The investigation remains ongoing.
Source: https://www.classaction.org/data-breach-lawsuits/nfm-lending-september-2026
NFM Lending cybersecurity rating report: https://www.rankiteo.com/company/nfmlending
"id": "NFM1788964331",
"linkid": "nfmlending",
"type": "Ransomware",
"date": "9/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1,000,000+ (clients and '
'employees)',
'industry': 'Financial Services',
'location': 'Maryland, USA',
'name': 'NFM Lending',
'type': 'Residential mortgage lender'}],
'data_breach': {'data_exfiltration': 'Alleged 2.5TB of data exposed',
'number_of_records_exposed': '1,000,000+',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Names',
'Social Security numbers',
'Financial details',
'Loan terms',
'Addresses',
'Contact information']},
'date_detected': '2026-09-07',
'date_publicly_disclosed': '2026-09-07',
'description': 'On September 7, 2026, the hacker group *Interlock* claimed '
'responsibility for a suspected ransomware attack on NFM '
'Lending, alleging the breach exposed over 2.5 terabytes of '
'sensitive data, including names, Social Security numbers, '
'financial details, loan terms, addresses, and contact '
'information belonging to more than 1 million clients and '
'employees.',
'impact': {'data_compromised': '2.5TB',
'identity_theft_risk': 'High',
'legal_liabilities': 'Potential class action lawsuit for privacy '
'violations, financial losses, and other '
'damages',
'payment_information_risk': 'High'},
'investigation_status': 'Ongoing',
'ransomware': {'data_exfiltration': 'Alleged 2.5TB of data exposed'},
'references': [{'date_accessed': '2026-09-07', 'source': 'Ransomware.live'}],
'regulatory_compliance': {'legal_actions': 'Potential class action lawsuit'},
'threat_actor': 'Interlock',
'title': 'NFM Lending Alleged Data Breach by Hacker Group Interlock',
'type': 'Ransomware'}