
American mortgage lender Plaza Home Mortgage said a data security incident it suffered in February compromised the sensitive personal information of over 135,000 customers.
Headquartered in San Diego, California, Plaza Home Mortgage is a financial services company specialising in wholesale and correspondent lending, partnering with mortgage brokers and other financial institutions rather than originating loans directly to the consumer community.
In a data security incident notice filed with the Office of Maine Attorney General, Plaza Home Mortgage said that on February 17, it experienced a data security incident in which an unauthorised party gained access to an employee’s computer. The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
“Threat actors illegally accessed our information systems without permission. Our security controls immediately informed us about the access, and we took action immediately to shut down the attack. Based on our investigation about this issue, an unauthorised party may have obtained some of your personal information,” Plaza said in its letter to affected customers.
The compromised data included names, addresses, social security numbers, birth dates, driver’s license or other government identification documents and more. The financial services company’s filing with the Maine state regulator revealed that at least 137,976 individuals were impacted by the incident.
“We took immediate actions to remove the threat actor from our systems and other security measures to further secure our information systems and your personal information. We have implemented additional organisational, technical and administrative security measures to prevent the recurrence of this security incident and to protect the personal information of our customers,” Plaza added.
The company has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general. It has also offered one year of complimentary identity protection and credit monitoring services through CyEx to all affected individuals.
In March, the Silent hacker group claimed responsibility for the cyber attack on Plaza Home Mortgage and listed the company as a victim on its data leak site. The group claimed to have exfiltrated confidential data from the company and threatened to release it publicly unless the company paid a ransom to regain access to the stolen files.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543