Another lender faces a class action case after ransomware claims

Img

Ransomware gangs continue to prey on mortgage lenders as a criminal group is taking credit for yet another hack at a large lender this month. 

Processing Content

The group known as BrainCipher says it exfiltrated over 10,300 documents from Gold Star Mortgage, according to screenshots of the group's post shared by cybersecurity blogs. The alleged attack follows a different cybercriminal outfit claiming an even larger hack of NFM Lending weeks ago.

A consumer filed a potential class action complaint against Gold Star for negligence last week, for the company's alleged failure to protect the personally identifiable information it holds. That case, which is not yet certified, resembles the plethora of litigation filed against other firms following their own data breach announcements.

The Ann Arbor, Michigan-based Gold Star generated over $2 billion in origination volume last year, and has 318 sponsored mortgage loan originators across 51 branches, according to publicly available data. The company has not disclosed any incident to various state attorneys general data breach databases, and didn't respond to requests for comment Monday.

The federal lawsuit filed in Michigan includes few details of the incident and does not estimate the number of potential victims. Attorneys who filed the suit also didn't return requests for comment Monday.

The data compromised from Gold Star includes lead sheets, credit reports, tax documents, income documents, and other materials containing Social Security numbers, according to the screenshot. BrainCipher claims the total files represent 10.5 gigabytes of data. 

If true, the scope would be a fraction of the over 2.5 terabytes of data the cybercriminals known as Interlock say they compromised from NFM Lending. That lender acknowledged an incident but did not share details of the attack, and said it took immediate actions to safeguard its systems. 

Mortgage industry in the crosshairs

The purported Gold Star hack marks the third announcement of an incident affecting a mortgage company this month. Pittsburgh-based HMA Mortgage this month also revealed an incident occurring last summer and affecting an untold number of individuals. 

Details of a breach rarely emerge, but a few lenders have admitted paying ransomware groups large sums to reacquire their PII. Flagstar revealed in court filings that it paid a $1 million bitcoin ransom to hackers to unlock its data in 2021, while Union Home Mortgage quietly disclosed a ransom payment in 2025. 

Dozens of other lenders have spent large sums to quell class action litigation. Real estate firms this summer agreed to pay out several millions of dollars in settlements covering over 800,000 combined class members. Those agreements came well ahead of consumers' attempts to certify their classes of affected members.