1.3 Million LoanCare Customers Have Personal, Financial Data Exposed – NMP Skip to main content

1.3 Million LoanCare Customers Have Personal, Financial Data Exposed

Jan 02, 2024
The Federal Deposit Insurance Corporation (FDIC) was the source of 10 of the 16 major information security incidents that occurred within the federal government during Fiscal Year 2016
Contributing Writer

Breach revealed in filing with Maine Attorney General a month after November 19 cyberattack.

The November 19 cyberattack that temporarily took down Fidelity National Financial’s online systems exposed the personal and financial data of 1.3 million customers of LoanCare, LLC, a mortgage subservicer owned by Fidelity National Financial, the real estate and mortgage industries’ largest underwriter of title insurance.

The breach of LoanCare, specifically, was not publicly known until December 20, when LoanCare filed a notice of data breach with the Attorney General of Maine. The filing indicates the data breach occurred on November 19, but was not discovered until December 13. 

However, letters being distributed to impacted customers by LoanCare state: “On or about November 19, 2023, LoanCare, LLC (“LoanCare”), which performs or has performed loan subservicing functions for your mortgage loan servicer, became aware of unauthorized access to certain systems within its parent’s, Fidelity National Financial, Inc. (“FNF”), information technology network. Upon becoming aware of the incident, FNF commenced an investigation with the assistance of third-party experts, notified certain law enforcement and governmental authorities, and began taking measures to assess and contain the incident.”

The SEC’s new rules for public companies’ cybersecurity disclosures, effective as of Sept. 5, 2023, includes “a requirement to disclose material cybersecurity incidents four business days after a public company determines the incident is material and a requirement to disclose annually information regarding cybersecurity risk management, strategy, and governance,” per the SEC’s website.

The only LoanCare customers receiving letters are those whose personal information was compromised.
 

About the author
Contributing Writer
Ryan Kingsley is a contributing writer for NMP.
Published
Jan 02, 2024
More from
Operations
MBA Expands CONVERGENCE With New Knowledge Hub For Lenders

iEmergent-powered dashboard gives mortgage professionals local market insights on demographics, affordability, and homeownership trends

Jun 25, 2026
First American Warns Against Title Insurance Cuts

Company argues efforts to lower closing costs could transfer risk to lenders, borrowers and investors

Jun 25, 2026
7 Profit-Boosting Lessons From NMP Ignite's 'Lean, Mean Mortgage Machine'

Mortgage leaders share how they're using AI, automation, lead management, staffing strategies and operational discipline to increase profitability in a margin-compressed market

Jun 24, 2026
Zillow Expands Into Mortgage Workflow With New Buyer Hub

New tools connect pre-approvals, loan officers, and home search in a unified platform

Jun 24, 2026
Rocket Pro Meets Brokers Halfway With ARIVE Expansion

Phase 2 of Rocket Pro’s integration lets brokers submit loan files and receive real-time status updates inside ARIVE

Jun 23, 2026