EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/mr-cooper-data-breach-2024
073/430

File EL-0358CriticalResolvedData Breach / Credential Theft / Data Exfiltration

Mr. Cooper Data Breach

Also filed as Nationstar Mortgage Data Leak · Mr. Cooper Group Breach

Mr. Cooper, one of America's largest mortgage servicers managing over $937 billion in servicing portfolio, suffered a massive data breach in late 2024 affecting approximately 14.6 million customers. The breach exposed Social Security numbers, bank account details, and comprehensive mortgage records.

  • #financial-services
  • #mortgage
  • #pii
  • #ssn-exposure
  • #class-action
  • #bank-accounts
  • #identity-theft
Notoriety9/10
Event
15 Oct 2024
Disclosed
18 Oct 2024
Target
Mr. Cooper
Scale
14.6M people
Status
Resolved

01Summary

In October 2024, cyber attackers gained unauthorized access to Mr. Cooper's internal systems through compromised employee credentials, successfully exfiltrating the personal data of approximately 14.6 million current and former customers over several days. The stolen dataset included full names, addresses, Social Security numbers, dates of birth, bank account numbers, mortgage loan details, complete payment histories, and escrow account information. The breach went undetected for an extended period before Mr. Cooper's security team identified unusual database access patterns. The company faced immediate consolidated class-action lawsuits alleging gross negligence in protecting sensitive customer financial data. Multiple state attorneys general launched investigations, and federal banking regulators including the CFPB began inquiries.

02Background

Mr. Cooper is one of the largest mortgage servicers in the United States, managing approximately 4.3 million customer accounts with a servicing portfolio valued at $937 billion. The company specializes in servicing mortgages originated by other lenders, handling payment collection, escrow management, and customer service.

03Key revelations

  1. 0114.6 million customers affected in one of the largest mortgage industry data breaches
  2. 02Social Security numbers and bank account details among exposed data
  3. 03Attack vector was compromised employee credentials from phishing
  4. 04Multiple consolidated class-action lawsuits filed within days
  5. 05CFPB and state attorneys general launched formal investigations

04Technical analysis

The breach resulted from compromised employee credentials, strongly suggesting a successful phishing campaign targeting employees with elevated system access. Attackers used legitimate VPN access to navigate internal systems over multiple days. The extended undetected presence indicates inadequate user behavior analytics and insufficient monitoring of privileged account activities.

Attack vector
Compromised employee credentials via targeted phishing campaign
Attack method
Credential theft with extended unauthorized access and bulk data exfiltration
Initial access
Targeted phishing campaign compromising employee VPN credentials
Exfiltration
Encrypted data extraction through legitimate VPN channels

Vulnerabilities exploited

  • Insufficient access controls
  • Inadequate monitoring

05Threat actor

Unknown threat actors believed to be financially motivated cybercriminals operating out of Eastern Europe. Stolen data valuable for identity theft and loan fraud operations.

Attribution sources

  • BleepingComputer
  • Media reports

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • Full names
  • Social Security numbers
  • Bank account numbers and routing details
  • Addresses
  • Dates of birth
  • Mortgage loan account numbers
  • Payment histories
  • Escrow account information

08Financial damage

Estimated total costs exceeding $200 million including notification, credit monitoring, legal defense, regulatory fines, IT remediation, and reputational damage. Stock declined 12% following disclosure.

09Timeline

  1. 2024-10-10Initial unauthorized access through compromised employee credentials
  2. 2024-10-15Breach detected by internal security team
  3. 2024-10-18Public disclosure; customer notification begins
  4. 2024-10-25First class-action lawsuit filed
  5. 2024-11-05Multiple lawsuits consolidated; CFPB announces investigation

10Reaction and fallout

Public reaction

Significant public outrage over mortgage data security. Thousands of customers reported fraudulent account activity and identity theft attempts following disclosure.

Political impact

Congressional inquiries into mortgage industry cybersecurity standards. Multi-state investigation led by Texas and California attorneys general.

11Legal

Multiple class-action lawsuits consolidated in US District Court for Northern District of Texas. CFPB and state regulatory investigations ongoing.

Civil lawsuits

  • Consolidated class-action: In re Mr. Cooper Data Breach Litigation

12Aftermath

Policy changes

  • Calls for enhanced cybersecurity requirements for mortgage servicers

Security improvements

  • Implementation of mandatory MFA for all employee accounts
  • Deployment of UEBA systems
  • Complete third-party security audit and penetration testing

13Significance and legacy

Significance

One of the largest and most sensitive mortgage industry data breaches, exposing the vulnerability of financial services to credential-based attacks and downstream risk to consumer financial security.

Legacy

The Mr. Cooper breach became a defining case study on protecting privileged employee credentials and implementing behavioral analytics for early breach detection in financial services.

14Disclosure and media

Authentication
Breach notification and media coverage

Publishing organisations

  • BleepingComputer

15Field notes

  1. 01Mr. Cooper services mortgages for approximately 1 in 20 American homeowners
  2. 02Stock dropped 12% within 48 hours, erasing approximately $400M in market capitalization

16Resolution

Investigation ongoing. Affected customers notified. Credit monitoring provided. Law enforcement investigation active.

17Sources

References

  1. [1]BleepingComputer: Mr. Cooper data breach impacts 14.6 million
  2. [2]Reuters: Mr. Cooper data breach
Fact sheetEL-0358

Dates

Event
15 Oct 2024
Started
15 Oct 2024
Discovered
15 Oct 2024
Disclosed
18 Oct 2024
Ongoing
No

Target

Organisation
Mr. Cooper Group Inc. (formerly Nationstar Mortgage)
Type
Financial Institution
Sector
Mortgage Servicing / Financial Services
Country
United States

Actor

Motivation
Financial gain through sale of stolen PII, Social Security numbers, and bank account details on underground markets for identity theft and fraud operations.
Attribution
Low
Arrested
No
Convicted
No

Data

People
14,600,000
Records
14,600,000
Sensitivity
Critical
Published
No
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.