Ally Bank Faces Class Action Lawsuit Over Data Breach – NMP Skip to main content

Ally Bank Faces Class Action Lawsuit Over Data Breach

Sep 10, 2024
The Federal Deposit Insurance Corporation (FDIC) was the source of 10 of the 16 major information security incidents that occurred within the federal government during Fiscal Year 2016
Associate Editor

The class members claim Ally Financial was negligent in safeguarding consumers' personal information

KEY TAKEAWAYS
  • Ally Financial faces a proposed class action lawsuit, filed September 7, stemming from a cyberattack and data breach.
  • Class members allege that Ally Financial was negligent and failed to implement “reasonable industry standard security practices.”
  • In 2023, there were 3,205 data compromises — up 78%.
  • Victims of the cyberattack assert claims of negligence, breach of implied contract, and unjust enrichment.

Cyberattacks on mortgage lenders continue, and without taking extensive measures to safeguard borrowers’ information, expect lawsuits follow. Stemming from a cyberattack and data breach that occurred at the end of August, Ally Financial Inc. and its subsidiary, Ally Bank, face a proposed class action lawsuit, filed September 7 in North Carolina federal court.

The plaintiff, Robert Hamilton, and class members allege that Ally Financial was negligent and failed to implement “reasonable industry standard security practices.” The plaintiff received a Notice of Data Breach letter dated Aug. 30, 2024, that occurred on an unspecified date. An unauthorized actor was able to access the Plaintiff’s private information through a vendor’s system, including the plaintiff’s name, social security number, date of birth, address, driver’s license number, email address, and phone number.

However, plaintiffs state in the lawsuit that Ally Financial and Ally Bank became aware of the cyberattack and data breach on Aug. 1, 2024,  prompting the lawsuit alleging negligence, breach of implied contract, and unjust enrichment.

An attorney representing the defendants did not provide an immediate response to a request for comment. 

The complaint also suggests that clients' stolen personal information could be sold on the dark web, stating, “numerous sources cite dark web pricing for stolen identity credentials.” The complaint lists dark-web prices on credit card details and bank logins as averaging from $40 to $200. 

Martin Walter, senior director at cybersecurity firm RedSeal, says that the stolen information and customer data from Ally Bank is actually much more valuable. “[C]ompared to credit card information, personally identifiable information and Social Security Numbers are worth more than 10x on the black market,” he explained.

The class members allege that the data breach was foreseeable, given the recent high profile data breaches at other leading financial firms, including Mr. Cooper, Fidelity National Financial, First American Financial Corporation, and loanDepot. Such cases have raised both the public's and businesses' awareness of the heightened risk that financial services companies face.

“Given the nature of Defendant’s Data Breach, as well as the long delay in notification to Class Members, it is foreseeable that the compromised PII has been or will be used by hackers and cybercriminals in a variety of devastating ways. Indeed, the cybercriminals who possess Plaintiffs’ and Class Members’ PII may easily obtain Plaintiffs’ and Class Members’ tax returns or open fraudulent credit card accounts in Class Members’ names,” the lawsuit reads.

The plaintiff and class members are seeking equitable relief pertaining to the “misuse and/or disclosure of private information,” and from “refusing to issue prompt, complete, any accurate disclosures.” The plaintiff, individually and on behalf of all class members, demands a trial by jury on all issues so triable. 

According to the 2023 Annual Data Breach Report, there were 3,205 data compromises in 2023, up 78% from 2022 (1,801 data compromises). The Identity Theft Resource Center set a new record for the number of data compromises tracked in a year, up 72% from the previous all-time high in 2021 (1,860).

About the author
Associate Editor
Katie Jensen is a mortgage news reporter at NMP.
Published
Sep 10, 2024
More from
Courts
AI Errors Leave Mortgage Trustee Without Brief In Foreclosure Appeal

Outside counsel’s fabricated citations expose a third-party oversight risk for mortgage servicers, trustees, and investors

Sep 10, 2026
Garg Pitches $2 Billion Better Turnaround; Board Calls Plan ‘Unworkable’

Former CEO targets zero monthly cash burn through higher mortgage volume, AI-driven operating changes, and $2 million in monthly savings

Sep 04, 2026
UWM’s $603 Million Hedge Loss Has Drawn Three Shareholder Lawsuits — So Far

One securities class action challenges UWM’s disclosures, while two newer stockholder suits target board oversight of the $27.5 billion derivatives position

Sep 03, 2026
Rocket Adds New Broker Allegations, Refinance Data To UWM Lawsuit

Amended complaint adds a named broker, new loan-level figures and a claim that damages have climbed to at least $100 million

Sep 01, 2026
Better’s $15 Million Offer To Garg Complicates Its Case Against Him

The mortgage lender portrayed its founder as unfit to lead, but Garg says it offered him a lucrative advisory role three days after firing him

Aug 26, 2026
Veterans United Fails To Knock Out Core RESPA Theory

The latest court order represents a significant 'mixed bag' for both sides

Aug 24, 2026