
Nevada-based Nations Direct Mortgage said more than 80,000 individuals were impacted by a significant data security incident it suffered last year.
Founded in 2007, Nations Direct Mortgage claims to be one of the top players in the U.S. residential mortgage industry. With more than 250 employees, the company offers a wide array of flexible mortgage products through business partners like Fannie Mae, Freddie Mac, and Ginnie Mae.
In a data security incident notice published on its website, the mortgage provider said that on December 30, it identified unauthorised access to certain systems within its internal network.
The company said it immediately launched an internal investigation, with assistance from third party cyber security experts, to understand the nature and scope of the incident and notified relevant law enforcement authorities about the incident.
“The investigation has determined that an unauthorised third party obtained access to and potentially removed data of certain individuals from across the country. As part of the review of the potentially impacted data, we and the third party experts retained by us have identified that some of your personal information may have been among that data,” reads the notice.
The compromised data included the names, addresses, social security numbers, and unique Nations Direct loan numbers of individuals associated with the company. The company said in a filing with the Office of the Maine Attorney General that as many as 83,108 individuals were affected by the data security incident.
“Upon learning of the incident, we promptly launched an investigation into the nature and scope of the incident and notified law enforcement. We also took immediate measures to further secure our information systems from further breach,” reads the notice filed with the state regulator.
While the mortgage lender did not find any evidence of the compromised data being misused, the possibility for the same cannot be ruled out. It has urged all affected individuals to remain vigilant, review their credit reports and financial statements on a regular basis, and report suspicious transactions to relevant law enforcement authorities. It is also offering two years of complimentary credit monitoring and identity theft protection services through Kroll to all the individuals affected by the data security incident.
Earlier this year, Utah-based independent mortgage provider, Academy Mortgage Corporation, revealed that it experienced a network security incident in March last year that involved a threat actor gaining unauthorised access to its internal network. The hacker disabled some of the company’s systems and stole the personal information of hundreds of thousands of customers.
The compromised data included customers’ names, dates of birth, and Social Security numbers. The company added that it had to store the information internally for standard payroll and organisational purposes. A filing with the state regulator of Maine revealed that at least 284,443 individuals were impacted by the data security incident.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543