Can Mortgage Lenders Prevent Cyberattacks?

Fintechs and mortgage companies can be easily exposed to cyberattacks. But does risk of exposure come down to digital competency or just plain luck?
Proof
June 27, 2022
Can Mortgage Lenders Prevent Cyberattacks?

Updated August 20, 2026

Mortgage lenders sit on some of the most valuable personal data in the financial system. Social Security numbers, bank account details, credit histories, wire instructions: a single loan file contains everything a criminal needs to commit identity theft, redirect funds, or hold an organization hostage. Attacks on the mortgage industry are not slowing down. The question is whether lenders can prevent cyberattacks, or whether the goal should be something more realistic: making every attack harder to execute and every authorization impossible to fake.

The honest answer is that no lender can prevent every cyberattack. But lenders that treat cybersecurity as a business control, rather than an IT expense, can dramatically reduce their exposure, contain breaches faster, and build records that hold up when disputes arise.

Key takeaways

  • Mortgage lenders cannot eliminate cyberattacks entirely, but proactive controls, vendor governance, and identity-linked records reduce both the frequency and the financial impact of breaches.
  • Generative AI has made phishing and business email compromise (BEC) far harder to detect. Attackers now produce flawless, personalized emails that bypass traditional red-flag training.
  • Penetration testing, multi-factor authentication (MFA), and rapid patch management are foundational controls that prevent the majority of attacks, according to security professionals who work directly with mortgage companies.
  • Cryptographically signed, identity-linked transaction records provide a defensible audit trail when a borrower or counterparty disputes an authorization after the fact.

Why mortgage lenders are a prime target

Mortgage companies hold more sensitive consumer data per transaction than almost any other industry. A single closing file contains a borrower's full legal name, date of birth, Social Security number, employment history, tax returns, bank statements, and wire instructions. Servicers hold that data for the life of the loan, sometimes decades.

Ransomware gangs and business email compromise operators both recognize this. Data is how mortgage companies, especially servicers, generate revenue. Holding it hostage or intercepting a wire transfer at closing produces an immediate, measurable payday.

The scale of recent breaches confirms the target. Mr. Cooper, loanDepot, Fidelity National Financial, First American Financial Corporation, Fairway Independent Mortgage, Planet Home Lending, and Academy Mortgage all disclosed significant incidents in 2023 and 2024. Mr. Cooper and loanDepot, both publicly traded, reported breach-related costs running into the millions in Securities and Exchange Commission (SEC) filings. The FBI opened an investigation into a cyberattack at SitusAMC, a third-party vendor serving JPMorgan Chase, Citi, and Morgan Stanley across the mortgage lifecycle.

Ike Suri, CEO of FundingShield, put it plainly: "Lenders and large institutions have always counted attacks as the cost of doing business and have wiped it under the rug. There was a spike during the pandemic and there continues to be a spike."

That posture is no longer sustainable, financially or legally.

Cyber risk is business risk

Many mortgage executives still treat cybersecurity investment as a non-revenue-generating expense, something to cut when margins compress. That framing is wrong, and it is costing companies money.

Michael Nouguier, chief information security officer at Richey May, a firm that advises mortgage companies on cybersecurity, hears the same objection repeatedly: "I don't want to know because then I have to do something about it." His response: "Turning a blind eye is just another term for risk acceptance."

Craig Mertens, principal architect at High Gravity, a cyber consulting firm, calls digital risks "uncaptured liabilities." A loan portfolio has a statistical model for default risk. Most mortgage companies have no equivalent model for what a network breach costs. Mertens estimates that small mortgage companies with 300 to 400 employees can experience tens of thousands of security events per day, most of them undetected.

The business consequences of a breach are immediate and compounding:

  • Loan origination systems go offline, halting closings and delaying funding
  • Borrower data lands on the dark web, triggering regulatory investigations and class-action lawsuits
  • Reputational damage erodes referral relationships with real estate agents and title companies
  • Breach response costs, including forensic investigation, legal counsel, and notification, arrive before any insurance recovery

Nouguier describes calls from mortgage company owners who are "crying" because nobody can email, systems are locked, and revenue is bleeding. "Those things were truly not considered ahead of time."

The biggest threat vector: third-party vendors

Third-party vendor vulnerabilities are the primary entry point for attackers targeting mortgage companies today. Most lenders rely on dozens of technology providers: loan origination systems, title software, appraisal platforms, credit reporting agencies, notary services, and closing technology vendors. Each connection is a potential door.

The "Citrix Bleed" exploit illustrates the risk precisely. Citrix Systems disclosed a critical vulnerability in its NetScaler ADC and Gateway software in August 2023. The Cybersecurity and Infrastructure Security Agency (CISA) issued guidance and Citrix began releasing patches in early October. Ransomware gangs AlphV and LockBit used the unpatched flaw to bypass MFA and hijack user sessions. Planet Home Lending, Academy Mortgage, and Fairway Independent Mortgage all disclosed breaches tied to this single vulnerability.

Fairway's regulatory filing noted that the company had not immediately implemented the available patch. In Massachusetts alone, 430 customers had their Social Security numbers, bank account information, and credit card numbers exposed. A timely patch would likely have prevented the breach.

Jeff Margolies, chief product and strategy officer at Saviynt, a security firm, frames the vendor problem this way: "You're only as secure as your weakest link. If you think of a typical ransomware kill chain, it usually starts with gaining access to someone's endpoints. A lot of financial services institutions have done a good job of educating employees to block those things, but not all third parties have these practices, so it's easier to take advantage of a vendor."

In November 2025, New American Funding disclosed a breach stemming from a third-party notary services vendor that exposed borrower names, addresses, and Social Security numbers used in loan closings. The breach originated outside the lender's own systems, but the lender bore the regulatory and reputational consequences.

What lenders can do about vendor risk

Vendor risk management requires active governance, not a one-time vendor questionnaire. Practical controls include:

  • Mapping every third-party vendor with access to your network or borrower data
  • Requiring vendors to carry their own cyber insurance and provide proof of SOC 2 Type 2 or equivalent certification
  • Actively monitoring vendor patch cycles and requiring timely updates as a contractual obligation
  • Restricting lateral movement by limiting what each vendor connection can access within your network
  • Removing vendor access immediately when a relationship ends or a contract changes

Suri believes the Consumer Financial Protection Bureau (CFPB) will publish more stringent third-party management regulations in the near term. Lenders that build governance programs now will be ahead of that requirement.

AI-powered phishing and business email compromise

Phishing has always been the lowest-friction attack vector. An employee clicks a link, credentials are captured, and an attacker is inside the network. What has changed is the quality of the attack.

Generative AI tools like ChatGPT and Anthropic's Claude produce flawless, grammatically perfect, contextually relevant emails. The traditional red flags, misspellings, broken English, generic greetings, are gone. Attackers now craft emails that reference specific transactions, impersonate known contacts, and match the tone of internal communications.

Nouguier explains the shift: "We used to train people to look for misspellings and grammatical errors, but now everybody just writes their emails in ChatGPT, so it's perfectly orchestrated. It is industry-focused and specific. It can really cater toward the individual. The ease of entry has just been truncated dramatically."

Business email compromise has become the dominant attack type in mortgage. Nouguier recently helped a mortgage client who accidentally paid a cybercriminal $19,000 because the ACH information on an invoice had been edited. The company's CFO paid the threat actor instead of the intended recipient. "That easily could have been $100,000," he says.

Caroline McCaffery, CEO of ClearOPS, notes that phishing now extends beyond email to SMS, a tactic called smishing. Either channel can initiate a ransomware attack or a wire fraud attempt.

Practical defenses against phishing

Technology alone cannot stop AI-powered phishing. Human awareness combined with technical controls is the effective combination:

  • Disable smart address display in email clients so the actual sending address is always visible. McCaffery notes that "almost nine times out of 10, if not higher, you'll be able to catch a phishing attempt just by looking at the actual email address because it often is from a Gmail account, not a corporate email."
  • Disable JavaScript rendering in email so messages display in plain text, making fraudulent links and embedded scripts visible immediately.
  • Implement MFA across all systems. Jordan Bingham, founder of LendSafe, estimates that simple actions like resetting passwords and requiring MFA can mitigate 80 to 90% of all attacks.
  • Run regular phishing simulations so employees encounter realistic attack scenarios before a real one arrives.
  • Establish out-of-band verification protocols for any wire transfer instruction received by email, requiring a phone call to a known number before funds move.

In-house security controls that reduce attack surface

Strong internal protocols are the foundation of any cyber defense program. Lenders that have cut cybersecurity spending during the market slowdown are taking on concentrated risk.

JT Gaietto, chief of staff at Digital Silence, wrote directly about this: "Mortgage lenders have stopped or dramatically stepped down their cyber spending due to the slowdown. A good pen test would help companies identify weaknesses in their portals, web applications, and other systems."

Penetration testing, or a pen test, is an exercise in which a cybersecurity expert attempts to find and exploit vulnerabilities in a company's systems before an attacker does. Companies that run pen tests regularly have a 30% higher chance of identifying weaknesses before they are exploited, according to research cited in the mortgage cybersecurity space.

Suri outlines the minimum internal standard: "Lenders need to ensure they have very vigilant procedures in place for data protection and always be up to speed on going through exercises like penetration testing in order to ensure they have an airtight solution before anything is put into production."

Core in-house controls include:

  • Role-based access control (RBAC) so employees can only access the data required for their specific function
  • Mandatory MFA for every system that stores or retrieves borrower data
  • Automated patch management with defined response windows for critical vulnerabilities
  • Encryption of all sensitive data in transit and at rest using current TLS protocols
  • Regular access audits to revoke credentials for terminated employees and inactive accounts
  • Offsite, encrypted backups that are isolated from the primary network so ransomware cannot encrypt them

The identity verification gap at closing

One area that competitors and industry commentary consistently underaddress is the moment of authorization itself. Most cybersecurity guidance focuses on keeping attackers out of systems. It does not address what happens when an attacker, or a fraudster posing as a legitimate borrower, reaches the transaction moment.

Wire fraud at closing is one of the most financially damaging attack types in mortgage. A borrower receives an email, apparently from their title company, with updated wire instructions. The email is from a compromised account or a spoofed address. The borrower wires funds to a criminal. Gina Johnson, co-owner of Lift Home Lending in Utah, describes a friend who lost $190,000 this way. "He's not your victim that's like 75 and doesn't know how to use a computer," she says. He was highly educated and doing business through a local credit union and title company.

The defense at this moment requires more than email security. It requires verifying that the person authorizing a transaction is who they claim to be, in real time, with a record that cannot be disputed later.

Cryptographic signing binds a transaction record to a verified legal identity and biometric. When a borrower claims "that wasn't me," a cryptographically signed record tied to identity verification and a live video session provides evidence that holds up in disputes and regulatory inquiries. MFA and encryption are necessary controls, but they do not produce this kind of defensible record.

Incident response: what to do when a breach happens

No security program eliminates breach risk entirely. Lenders need a tested incident response plan before an attack occurs, not during one.

McCaffery outlines the immediate priorities: "You have to be really well practiced in what to do in response to the attack. Maybe you contact your insurance company, find out if they will let you pay a ransom. Check your backup systems, can you default to it, can you also protect the backup from hackers, do you have a backup to your backup?"

A functional incident response plan covers:

  • Designated incident response roles and contact lists, including legal counsel, cyber insurance carrier, and forensic investigators
  • Documented breach notification procedures for each applicable regulator, with timelines mapped to GLBA, NYDFS, Ginnie Mae, and state law requirements
  • Tested backup and recovery procedures, including isolated backups that ransomware cannot reach
  • Communication protocols for borrowers, partners, and regulators that do not admit liability prematurely
  • Post-incident review to identify the entry point and close it before returning to normal operations

The companies that navigate breaches with the least damage are those that have practiced their response. Demonstrating strong awareness of the risk also plays better than negligence in courtrooms, according to security professionals who have testified in breach-related litigation.

Building a defensible security posture

The goal is not a perfect perimeter. The goal is a security posture that makes attacks harder to execute, contains damage when they succeed, and produces records that are defensible in regulatory inquiries and legal disputes.

Lenders that achieve this posture share several characteristics:

  • They treat cybersecurity spending as a business control with a measurable return, not a cost center
  • They run active vendor governance programs, not one-time questionnaires
  • They test their defenses regularly through penetration testing and phishing simulations
  • They maintain incident response plans that have been rehearsed, not just written
  • They use identity-linked, cryptographically signed records for high-value authorizations so disputes can be resolved with evidence rather than assertions
  • They stay current on regulatory requirements across every jurisdiction where they operate

The mortgage industry's cyber threat environment will continue to intensify. Generative AI lowers the cost of sophisticated attacks. Third-party ecosystems expand the attack surface. Regulatory expectations are rising faster than most companies' security maturity.

Lenders that invest now, in governance, in controls, and in defensible authorization records, will be better positioned to operate when the next major breach hits the industry. And based on recent history, it will.

See how Proof Defend protects mortgage transactions with cross-platform fraud detection and deepfake analysis.

graphic of envelop on a square

Subscribe to our newsletter

Related Articles