Lennar Mortgage says breaches affected tens of thousands of consumers

Img

Lennar Mortgage is the latest lender to suffer a data breach, revealing that it dealt with two separate incidents earlier this year. 

Processing Content

The lending arm of the home building giant said the incursions may have involved the personal identifiable information of at least 61,000 Texans, according to a public disclosure last week. The company said the attacks occurred between May 26, 2026 and June 1. 

"We recently identified two separate, and we believe, unrelated social engineering-based cybersecurity events involving unauthorized access to certain company systems within Lennar and Lennar Mortgage, respectively," a spokesperson said in a statement Monday. 

The company said there was no operational impact from the incidents, and did not reveal the total number of consumers who may have been affected nationwide. 

Two consumers have also quickly filed class action claims for negligence against Lennar in a Florida federal court for failing to protect their personally identifiable information. In its notice to consumers, Lennar said it wasn't aware of any misuse of customers' PII such as Social Security numbers. 

The company said it implemented additional security measures following the incident, and according to its notice to impacted consumers is offering two years of complimentary identity theft monitoring services.

"We take seriously the trust our Associates, customers, and partners place in us," the company's statement read. ".... We remain committed to protecting the information entrusted to us and, above all, the people who placed it in our care."

Lennar is one of the nation's largest home builders and like its peers has posted large net profits in recent quarters, although it has acknowledged the numerous headwinds facing home builders. The company posted a $305 million net profit in the second quarter, and delivered over 20,000 homes during the recently reported period. 

Breach-and-litigation cycle continues

The two lawsuits, filed by a former employee and a customer, are similar to the numerous complaints that inundate firms following data breach disclosures. One of the suits asks Lennar to delete the stored PII of potential data breach victims, and to maintain stronger cybersecurity controls. 

Five mortgage companies have agreed to data breach settlements this year, headlined by Bayview Asset Management's $26 million deal for over 5.7 million affected consumers. Other settlements include: 

  • AnnieMac, $2 million for 171,074 class members;
  • SitusAMC, $5.3 million for 662,792 class members;
  • McLean Mortgage, payments on a per-claim basis for 30,453 class members;
  • NJ Lenders Corp., $100,000 for a class of approximately 30,000 class members.

The Guild Mortgage-owned Academy Mortgage is also on the verge of producing a preliminary settlement agreement with plaintiffs for a 2023 breach which affected 284,443 customers. The California Department of Financial Protection and Innovation last week fined the company $825,000 over the attack, as states continue to ramp up enforcement of the home loan space.