EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/ransomware/loandepot-ransomware-attack-2024
120/430

File EL-0311CriticalResolvedRansomware / Ransomware with Data Exfiltration

LoanDepot Ransomware Attack

Also filed as LoanDepot Data Breach · LoanDepot Cyber Incident

LoanDepot, one of America's largest mortgage lenders, was struck by a ransomware attack in January 2024 that compromised the personal data of approximately 16.9 million customers and forced the company to temporarily halt all loan processing operations nationwide.

  • #financial-services
  • #mortgage-lending
  • #ransomware
  • #pii
  • #ssn-exposure
  • #class-action
  • #operations-disrupted
Notoriety9/10
Event
8 Jan 2024
Disclosed
15 Jan 2024
Target
LoanDepot
Scale
16.9M people
Status
Resolved

01Summary

On January 8, 2024, LoanDepot suffered a ransomware attack that encrypted internal systems and forced the immediate shutdown of all loan origination and processing systems. The attack occurred at a particularly damaging time as interest rates were fluctuating and the mortgage market was already under pressure. Threat actors exfiltrated approximately 16.9 million customer records containing highly sensitive data including names, addresses, Social Security numbers, loan account details, financial transaction records, property addresses, and escrow account information. The company was unable to process loan payments, fund new loans, or handle customer inquiries for over a week. LoanDepot faced multiple class-action lawsuits alleging negligence in data protection.

02Background

LoanDepot is one of the largest non-bank mortgage lenders in the United States, originating billions of dollars in home loans annually. The company operates primarily online and through a network of loan officers nationwide.

03Key revelations

  1. 0116.9 million customers affected in one of the largest financial sector ransomware attacks
  2. 02Company forced to halt all loan processing operations for over a week
  3. 03SSNs and financial account details among stolen data
  4. 04Multiple class-action lawsuits consolidated against the company

04Technical analysis

The ransomware attack encrypted LoanDepot's core systems including loan origination platforms, customer databases, and payment processing systems. The attackers gained initial access through a compromised employee account with elevated privileges, using phishing credentials. They deployed ransomware across the network after exfiltrating data over a period of days.

Attack vector
Compromised employee credentials via phishing, then ransomware deployment
Attack method
Ransomware encryption with prior data exfiltration (double extortion)
Initial access
Phishing campaign compromising employee credentials
Exfiltration
Bulk data extraction prior to ransomware deployment

05Threat actor

Unknown ransomware group. The attack showed characteristics of a sophisticated operation with exfiltration before encryption, suggesting an established ransomware affiliate operation.

Attribution sources

  • BleepingComputer
  • Media reports

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • Full names
  • Social Security numbers
  • Addresses
  • Loan account numbers
  • Financial transaction records
  • Property addresses
  • Escrow account information
  • Dates of birth

08Financial damage

LoanDepot reported material financial impact including loss of loan origination revenue during shutdown, IT remediation costs, legal fees, and potential regulatory fines. Estimated total impact exceeding $150 million.

09Timeline

  1. 2024-01-08Ransomware attack detected; systems taken offline
  2. 2024-01-09Loan processing halted nationwide
  3. 2024-01-15Initial customer notification of data breach
  4. 2024-02-01Class-action lawsuits filed
  5. 2024-03-15Systems fully restored

10Reaction and fallout

Public reaction

Significant customer anger as homeowners were unable to make payments or close loans. Many reported their Social Security numbers were compromised.

Political impact

Congressional scrutiny of non-bank mortgage lender cybersecurity preparedness. CFPB opened investigation into data protection practices.

11Legal

Multiple class-action lawsuits consolidated in federal court. Regulatory investigations by CFPB and state authorities ongoing.

Civil lawsuits

  • Consolidated class-action: In re LoanDepot Data Breach Litigation

12Aftermath

Policy changes

  • Calls for enhanced cybersecurity requirements for non-bank mortgage lenders

Security improvements

  • Complete IT infrastructure overhaul
  • Enhanced endpoint detection and response deployment
  • Improved backup and disaster recovery systems

13Significance and legacy

Significance

One of the most disruptive ransomware attacks on a financial institution, demonstrating the operational fragility of digital-first mortgage lending.

Legacy

LoanDepot became a cautionary tale for the financial services industry about the catastrophic operational impact of ransomware on digital lending platforms.

14Disclosure and media

Authentication
Breach notification and media coverage

Publishing organisations

  • BleepingComputer

15Field notes

  1. 01LoanDepot's stock dropped over 30% in the weeks following the attack
  2. 02The company had to manually process urgent loan requests using paper forms during the outage

16Resolution

Systems restored over several weeks. Customer notification completed. Credit monitoring offered. Investigation ongoing.

17Sources

References

  1. [1]BleepingComputer: LoanDepot ransomware attack impacts 16.9M
  2. [2]Reuters: LoanDepot cyberattack
  3. [3]SEC Filing: LoanDepot 8-K disclosure
Fact sheetEL-0311

Dates

Event
8 Jan 2024
Started
8 Jan 2024
Duration
67 days
Discovered
8 Jan 2024
Disclosed
15 Jan 2024
Resolved
15 Mar 2024
Ongoing
No

Target

Organisation
LoanDepot.com, LLC
Type
Financial Institution
Sector
Mortgage Lending / Financial Services
Country
United States

Actor

Motivation
Financial gain through ransomware extortion combined with theft of personally identifiable information for sale on underground markets.
Attribution
Low
Arrested
No
Convicted
No

Data

People
16,900,000
Records
16,900,000
Sensitivity
Critical
Published
No
Sold (dark web)
Yes

Money

Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.