Ally Bank Faces Class Action Lawsuit Over Data Breach – NMP Skip to main content

Ally Bank Faces Class Action Lawsuit Over Data Breach

Sep 10, 2024
The Federal Deposit Insurance Corporation (FDIC) was the source of 10 of the 16 major information security incidents that occurred within the federal government during Fiscal Year 2016
Associate Editor

The class members claim Ally Financial was negligent in safeguarding consumers' personal information

KEY TAKEAWAYS
  • Ally Financial faces a proposed class action lawsuit, filed September 7, stemming from a cyberattack and data breach.
  • Class members allege that Ally Financial was negligent and failed to implement “reasonable industry standard security practices.”
  • In 2023, there were 3,205 data compromises — up 78%.
  • Victims of the cyberattack assert claims of negligence, breach of implied contract, and unjust enrichment.

Cyberattacks on mortgage lenders continue, and without taking extensive measures to safeguard borrowers’ information, expect lawsuits follow. Stemming from a cyberattack and data breach that occurred at the end of August, Ally Financial Inc. and its subsidiary, Ally Bank, face a proposed class action lawsuit, filed September 7 in North Carolina federal court.

The plaintiff, Robert Hamilton, and class members allege that Ally Financial was negligent and failed to implement “reasonable industry standard security practices.” The plaintiff received a Notice of Data Breach letter dated Aug. 30, 2024, that occurred on an unspecified date. An unauthorized actor was able to access the Plaintiff’s private information through a vendor’s system, including the plaintiff’s name, social security number, date of birth, address, driver’s license number, email address, and phone number.

However, plaintiffs state in the lawsuit that Ally Financial and Ally Bank became aware of the cyberattack and data breach on Aug. 1, 2024,  prompting the lawsuit alleging negligence, breach of implied contract, and unjust enrichment.

An attorney representing the defendants did not provide an immediate response to a request for comment. 

The complaint also suggests that clients' stolen personal information could be sold on the dark web, stating, “numerous sources cite dark web pricing for stolen identity credentials.” The complaint lists dark-web prices on credit card details and bank logins as averaging from $40 to $200. 

Martin Walter, senior director at cybersecurity firm RedSeal, says that the stolen information and customer data from Ally Bank is actually much more valuable. “[C]ompared to credit card information, personally identifiable information and Social Security Numbers are worth more than 10x on the black market,” he explained.

The class members allege that the data breach was foreseeable, given the recent high profile data breaches at other leading financial firms, including Mr. Cooper, Fidelity National Financial, First American Financial Corporation, and loanDepot. Such cases have raised both the public's and businesses' awareness of the heightened risk that financial services companies face.

“Given the nature of Defendant’s Data Breach, as well as the long delay in notification to Class Members, it is foreseeable that the compromised PII has been or will be used by hackers and cybercriminals in a variety of devastating ways. Indeed, the cybercriminals who possess Plaintiffs’ and Class Members’ PII may easily obtain Plaintiffs’ and Class Members’ tax returns or open fraudulent credit card accounts in Class Members’ names,” the lawsuit reads.

The plaintiff and class members are seeking equitable relief pertaining to the “misuse and/or disclosure of private information,” and from “refusing to issue prompt, complete, any accurate disclosures.” The plaintiff, individually and on behalf of all class members, demands a trial by jury on all issues so triable. 

According to the 2023 Annual Data Breach Report, there were 3,205 data compromises in 2023, up 78% from 2022 (1,801 data compromises). The Identity Theft Resource Center set a new record for the number of data compromises tracked in a year, up 72% from the previous all-time high in 2021 (1,860).

About the author
Associate Editor
Katie Jensen is a mortgage news reporter at NMP.
Published
Sep 10, 2024
More from
Courts
Better Deploys Poison Pill In Escalating Fight With Garg

The shareholder rights plan adds a 15% ownership trigger while the former CEO solicits shareholder consent to remove five of Better’s eight directors

Aug 20, 2026
Better Sues Garg After His Claimed Voting Majority Falls Short

The former CEO acknowledges an “administrative error” left him without enough consents to remove five directors, but his formal campaign for board control is moving forward

Aug 19, 2026
Two Harbors Responds To UWM Lawsuit; Ishbia Reassures Brokers

Two Harbors disputes UWM’s claims and questions its $603.2 million derivatives loss, while Ishbia says the wholesale lender has never been stronger

Aug 12, 2026
UWM Seeks More Than $500M From Two Harbors After Failed Deal

Lender alleges Two Harbors undermined their merger and steered the company toward CrossCountry, turning a costly acquisition failure into a federal court fight

Aug 10, 2026
UWM Previews Bid To Dismiss Rocket’s $100M Servicing Lawsuit

UWM argues Refi75 was permissible mass advertising

Jul 27, 2026
Kortas Secures Sole Ownership Of NEXA Lending

The settlement ends a multiyear legal battle between the co-founders of NEXA Lending

Jul 20, 2026