ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

loanDepot takes systems offline to deal with a serious ransomware incident

Linked InXFacebook
bookmark_borderSave to Library

LoanDepot, one of America’s largest mortgage lenders, said it suffered a significant ransomware attack that disrupted operations and forced it to take several systems offline.Last week, loanDepot customers started reporting issues when trying to log on to the company’s payment portal or contacting them by phone. Several customers took to social media to report the outage, and loanDepot replied to them confirming that it was dealing with a cyber security incident.“loanDepot is experiencing a cyber incident, which is affecting our phone lines. We are working diligently to return to normal business operations as soon as possible. We apologise for the inconvenience,” the company wrote on X, formerly Twitter, in response to customer complaints.On January 8, the mortgage lender uploaded a similar statement on its official website to confirm that it was dealing with a serious cyber security incident.“loanDepot is experiencing a cyber incident. We have taken certain systems offline and are working diligently to restore normal business operations as quickly as possible. We are working quickly to understand the extent of the incident and taking steps to minimize its impact.“The Company has retained leading forensics experts to aid in our investigation and is working with law enforcement. We sincerely apologize for any impacts to our customers and we are focused on resolving these matters as soon as possible,” reads the statement.The company informed customers on social media channels that automatic payments will still be processed, but there will be a delay in uploading their payment details on the payment history tab.In an 8-K filing with the U.S. Securities and Exchange Commission, loanDepot said that the threat actors not only infiltrated its internal network, but encrypted certain data. To mitigate the impact of the ransomware attack, the company was forced to take certain systems offline while it continues to implement measures to secure its business operations, bring its systems back online and respond to the incident.“The Company will continue to assess the impact of the incident and whether the incident may have a material impact on the Company,” the company said in its SEC filing.As of now, no criminal group has claimed responsibility for the ransomware attack and the company has not let out details about who is behind the cyber attack, whether any data was exfiltrated from its network or if it has received a ransom demand.Last year, another U.S mortgage giant, Mr. Cooper, said that it detected suspicious activities in certain parts of its internal network on 31st October.“Through our investigation, we determined that there was unauthorised access to certain of our systems between October 30, 2023 and November 1, 2023. During this period, we identified that files containing personal information were obtained by an unauthorised party,” the company said in a filing with the Office of the Maine Attorney General.The mortgage provider’s internal investigation revealed that the cyber incident compromised customers’ personal information such as their names, addresses, phone numbers, Social Security numbers, dates of birth, and financial account details including bank account numbers. The company’s filing with the regulator also revealed that at least 14,690,284 individuals were impacted by the data security incident.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543