Industry News
The U.S. mortgage company LoanDepot has been hit by an alleged ransomware attack.
LoanDepot, a U.S.-based mortgage lending company, said it is dealing with an alleged ransomware attack and is currently working to quickly resume its normal business operations.
On January 8, LoanDepot confirmed the incident in a regulatory filing with the U.S. Securities and Exchange Commission (SEC).
"Although our investigation is ongoing, at this stage, the company has determined that the unauthorized activity by a third party involved accessing certain company systems and encrypting data," LoanDepot said in the statement.
In a statement posted on the company's website, LoanDepot said it had taken certain systems offline and is working to determine the extent of the cyberattack.
An error message on a LoanDepot login screen indicates that recurring automatic payments are being processed as expected. However, there may be a temporary delay before users see these payments reflected in their payment histories.
"We sincerely apologize for any inconvenience this may have caused our customers, and we are focused on resolving these issues as soon as possible," LoanDepot said.
The company launched an investigation with the assistance of leading, unnamed cybersecurity experts and began the process of notifying the relevant regulators and law enforcement agencies.
Given the data theft and encryption, the cyberattack on LoanDepot is suspected to be a ransomware attack. However, no ransomware group has claimed responsibility for the attack so far.
Since December, new SEC breach reporting rules have required companies to promptly notify regulators of cybersecurity incidents that have a significant impact on their business. Announced in July, these new rules aim to make cybersecurity disclosures more consistent, comparable, and useful, benefiting investors, companies, and the markets that connect them.
In April 2023, LoanDepot announced that it ranked third among the largest mortgage lenders in the United States in terms of the number of loans funded, according to 2022 Home Mortgage Disclosure Act data collected by the Consumer Financial Protection Bureau.
The cyberattack on LoanDepot is part of a series of incidents targeting the lending and mortgage industry. In November, a ransomware attack on insurance provider Fidelity National Financial left the company offline for more than a week.
A month later, the mortgage lender Mr. Cooper disclosed a security breach in October that affected more than 14 million customers. In response to the incident, Mr. Cooper announced additional spending of at least 19.6 million pounds ($25 million) to monitor the credit of affected customers.
Dan Lattimer, vice president for the United Kingdom and Ireland at the IT and network security company Semperis, emphasized that recent cyberattacks highlight the daily challenges organizations face in protecting their proprietary data.
"Today, most of the global heavyweights in the mortgage and lending industry have implemented fairly robust security strategies to protect sensitive data. Unfortunately, persistent threat actors will target specific companies and search for gaps in their security architecture until they find a weakness," Lattimer said.
In October, BT released data showing that more than 530 potential cyberattack signals are detected by companies every second. As businesses of all sizes go digital, the industries most frequently targeted over the past 12 months have been IT, defense, banking, and insurance. A total of 19.7% of malware detections are directed at these high-stakes targets.
In November, a division of the Industrial and Commercial Bank of China was the victim of a ransomware attack. The attack caused disruptions in the U.S. Treasury market, leading to the settlement of fixed-income and equity trades.
Lattimer added that phishing scams remain highly effective at infiltrating organizations, with hackers sending emails to a wide range of employees within a company and waiting for someone to inadvertently click on an attachment containing malicious code.
Although persistent threat actors will eventually reach a target, Lattimer said that what happens next is the decisive factor in determining whether the illegal activity results in financial loss, causes business disruptions, and ultimately makes headlines. Lattimer emphasized that organizations must take the initiative against attackers and improve their resilience.
"Cybersecurity is a combat sport and isn't for the faint of heart. Take the scourge of ransomware, for example. No one can pay their way out of a ransomware attack. Preparing in peacetime is key, and if you only discover the attack because the criminals have sent the ransom note, it's too late," Lattimer added.
In its annual ransomware survey, Hornetsecurity revealed that more than nine out of ten companies (92.5%) are aware of the potential negative impact of ransomware, but only 54% of respondents said their management is “actively involved in discussions and decision-making” regarding the prevention of such attacks. Four in ten (39.7%) said they were content to “leave it to the IT department to resolve the issue.”
Reassuringly, 93.2% of respondents consider protection against ransomware to be “very” to “extremely” important in terms of their organization’s IT priorities, and 87.8% of respondents confirmed that they have a disaster recovery plan in place in the event of a ransomware attack.
Lattimer added that securing identity systems is one of the most critical components of an organization's risk management program. When Active Directory services within the identity system are compromised, hackers have obtained the "keys to the kingdom" and can freely siphon off vast amounts of proprietary data.
Cloud & AI Infrastructure
Cloud & Cyber Security
Data & AI Leaders Summit
Data Centre World